Severity
5.5MEDIUM
EPSS
0.1%
top 71.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 17

Description

MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access vulnerabilities, leading to sensitive information leakage.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5huawei_technologies_co.,_ltd./nice-al00Earlier than Nice-AL00C00B160 versions, Earlier than Nice-AL10C00B140 versions

🔴Vulnerability Details

2
GHSA
GHSA-m9qj-8whm-9cg3: MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory a2022-05-17
CVEList
CVE-2017-8184: MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory a2017-11-22

📋Vendor Advisories

1
Red Hat
liblouis: incomplete fix for CVE-2014-81842017-11-02

💬Community

1
Bugzilla
CVE-2017-15101 liblouis: incomplete fix for CVE-2014-81842017-11-08
CVE-2017-8184 (MEDIUM CVSS 5.5) | MTK platform in Huawei smart phones | cvebase.io