CVE-2017-0461
published 2017-03-08CVE-2017-0461: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission…
PriorityP418medium4.7CVSS 3.0
AVLACHPRNUIRSUCHINAN
EPSS
0.87%
54.6th percentile
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32073794. References: QC-CR#1100132.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwgv-w78x-v7p3: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permissi
ghsa_unreviewed·2022-05-17
CVE-2017-0461 [MEDIUM] CWE-200 GHSA-wwgv-w78x-v7p3: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permissi
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32073794. References: QC-CR#1100132.
OSV
CVE-2017-0461: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permissi
osv·2017-03-08·CVSS 4.7
CVE-2017-0461 [MEDIUM] CVE-2017-0461: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permissi
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32073794. References: QC-CR#1100132.
Android
CVE-2017-0461: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0461
Severity: MEDIUM
References: A-32073794
QC-CR#1100132
vendor_android·2017-03-01·CVSS 4.7
CVE-2017-0461 [MEDIUM] CVE-2017-0461: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0461
Severity: MEDIUM
References: A-32073794
QC-CR#1100132
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0461
Severity: MEDIUM
References: A-32073794
QC-CR#1100132
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5401 Mozilla: Memory Corruption when handling ErrorResult (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 9.8
CVE-2017-5401 [CRITICAL] CVE-2017-5401 Mozilla: Memory Corruption when handling ErrorResult (MFSA 2017-06)
CVE-2017-5401 Mozilla: Memory Corruption when handling ErrorResult (MFSA 2017-06)
A crash triggerable by web content in which an ErrorResult references unassigned memory due to a logic error. The resulting crash may be exploitable.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5401
Acknowledgements:
Name: the Mozilla project
Upstream: Anton Eliasson
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-0459.html
---
This issue has been addressed in
Bugzilla
CVE-2017-5410 Mozilla: Memory corruption during JavaScript garbage collection incremental sweeping (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 9.8
CVE-2017-5410 [CRITICAL] CVE-2017-5410 Mozilla: Memory corruption during JavaScript garbage collection incremental sweeping (MFSA 2017-06)
CVE-2017-5410 Mozilla: Memory corruption during JavaScript garbage collection incremental sweeping (MFSA 2017-06)
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5410
Acknowledgements:
Name: the Mozilla project
Upstream: Jerri Rice
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-20
Bugzilla
CVE-2017-5400 Mozilla: asm.js JIT-spray bypass of ASLR and DEP (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 9.8
CVE-2017-5400 [CRITICAL] CVE-2017-5400 Mozilla: asm.js JIT-spray bypass of ASLR and DEP (MFSA 2017-06)
CVE-2017-5400 Mozilla: asm.js JIT-spray bypass of ASLR and DEP (MFSA 2017-06)
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5400
Acknowledgements:
Name: the Mozilla project
Upstream: Rh0
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-0459.html
---
This issue has been addressed in the following
Bugzilla
CVE-2017-5402 Mozilla: Use-after-free working with events in FontFace objects (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 9.8
CVE-2017-5402 [CRITICAL] CVE-2017-5402 Mozilla: Use-after-free working with events in FontFace objects (MFSA 2017-06)
CVE-2017-5402 Mozilla: Use-after-free working with events in FontFace objects (MFSA 2017-06)
A use-after-free can occur when events are fired for a FontFace object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5402
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-04
Bugzilla
CVE-2017-5405 Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 5.3
CVE-2017-5405 [MEDIUM] CVE-2017-5405 Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06)
CVE-2017-5405 Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06)
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5405
Acknowledgements:
Name: the Mozilla project
Upstream: Anonymous
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-0459.html
---
This issue has been addressed in the following
Bugzilla
CVE-2017-5407 Mozilla: Pixel and history stealing via floating-point timing side channel with SVG filters (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 6.5
CVE-2017-5407 [MEDIUM] CVE-2017-5407 Mozilla: Pixel and history stealing via floating-point timing side channel with SVG filters (MFSA 2017-06)
CVE-2017-5407 Mozilla: Pixel and history stealing via floating-point timing side channel with SVG filters (MFSA 2017-06)
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5407
Acknowledgements:
Name: the Mozilla project
Upstream: David Kohlbrenner
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been
Bugzilla
CVE-2017-5408 Mozilla: Cross-origin reading of video captions in violation of CORS (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 5.3
CVE-2017-5408 [MEDIUM] CVE-2017-5408 Mozilla: Cross-origin reading of video captions in violation of CORS (MFSA 2017-06)
CVE-2017-5408 Mozilla: Cross-origin reading of video captions in violation of CORS (MFSA 2017-06)
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5408
Acknowledgements:
Name: the Mozilla project
Upstream: Eric Lawrence of Chrome Security
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://r
Bugzilla
CVE-2017-5404 Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
bugzilla·2017-03-07·CVSS 9.8
CVE-2017-5404 [CRITICAL] CVE-2017-5404 Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
CVE-2017-5404 Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5404
Acknowledgements:
Name: the Mozilla project
Upstream: Ivan Fratric of Google Project Zero
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2017:0459 https://rhn.redhat
http://www.securityfocus.com/bid/96743http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=ce5d6f84420a2e6ca6aad6b866992970dd313a65https://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.securityfocus.com/bid/96743http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=ce5d6f84420a2e6ca6aad6b866992970dd313a65
2017-03-08
Published