CVE-2017-0432
published 2017-02-08CVE-2017-0432: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the…
PriorityP433high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
2.10%
79.7th percentile
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-28332719.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x8p2-4582-wcx4: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context
ghsa_unreviewed·2022-05-13
CVE-2017-0432 [HIGH] GHSA-x8p2-4582-wcx4: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-28332719.
OSV
CVE-2017-0432: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context
osv·2017-02-08·CVSS 7.0
CVE-2017-0432 [HIGH] CVE-2017-0432: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-28332719.
Android
CVE-2017-0432: Android Security Bulletin 2017-02-01
CVE: CVE-2017-0432
Severity: HIGH
References: A-28332719*
M-ALPS02708925
vendor_android·2017-02-01·CVSS 7.0
CVE-2017-0432 [HIGH] CVE-2017-0432: Android Security Bulletin 2017-02-01
CVE: CVE-2017-0432
Severity: HIGH
References: A-28332719*
M-ALPS02708925
Android Security Bulletin 2017-02-01
CVE: CVE-2017-0432
Severity: HIGH
References: A-28332719*
M-ALPS02708925
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62.
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google and used in the Chrome web browser, online services, and other st
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62 .
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google a
2017-02-08
Published