CVE-2017-14875 describes a heap overread vulnerability within the VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE ioctl handler in Android for MSM, Firefox OS for MSM, and QRD Android versions released before May 23, 2017. This vulnerability carries a CVSS v3.0 score of 7.5 (HIGH), indicating a high-impact issue that could lead to unauthorized information disclosure (C:H) without requiring user interaction or elevated privileges. While the vulnerability is remotely exploitable (AV:N), there is currently no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.