CVE-2017-8278 is a high-severity buffer or integer overflow vulnerability affecting Qualcomm products running Android releases from CAF using the Linux kernel. An unauthenticated attacker could exploit this flaw by tricking a user into interacting with a malicious application, leading to complete compromise of confidentiality, integrity, and availability. Despite its high CVSS score of 7.8, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.