CVE-2017-14872 is a buffer over-read vulnerability affecting Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before the 2018-06-05 security patch level. It occurs during meta image flashing when the number of images exceeds the maximum range of 32. Rated as Medium severity (CVSS 5.5), this vulnerability has a local attack vector with low attack complexity, requiring local privileges. A successful exploit could lead to high confidentiality impact, but no integrity or availability impact. There is no evidence of active exploitation, and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.