CVE-2015-8319Improper Restriction of Operations within the Bounds of a Memory Buffer in Huawei Mate S Firmware

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateMay 17

Description

Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted applicati

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDhuawei/mate_s_firmwarecrr-cl00, crr-tl00, crr-ul00+2
NVDhuawei/p8_firmware5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-xfv9-m9ch-5j87: Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230,2022-05-17
CVEList
CVE-2015-8319: Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230,2016-04-07
CVE-2015-8319 — Huawei Mate S Firmware vulnerability | cvebase