CVE-2018-11280 PUBLISHED CVSS 4.900000095367432 MEDIUM

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing user-space there is no size validation of the NAT entry input. If the user input size of the NAT entry is greater than the max allowed size, memory exhaustion will occur.

EPSS 0.03% · 8.7th percentile

Risk Scores

CVSS v2.0
4.900000095367432
EPSS Score
0.03%
8.7th percentile

Affected Products

VendorProductVersions
Qualcomm, Inc.Android for MSM, Firefox OS for MSM, QRD AndroidAll Android releases from CAF using the Linux kernel
googleandroid

Timeline

References

Open in Interactive Console →