V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-0855
CVE
High

In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memor…

CVSS
7.5
High
EPSS
0.02
p85
Published
2017-01-01
Updated
2017-01-01
Description

In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64452857.

Tags · CWE
Pre-auth
CWE-772
CAPEC-469
Affected products
Android
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.023 · p85
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-469 · CWE-772
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefoxTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
android*Tracked
Source databases
CVE
UBU