VDB
CVE-2018-9381
CVE-2018-9381
PUBLISHED
CVSS 7.5 HIGH
In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
EPSS 0.25% · 16.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.25%
16.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 8.1 | |
| android | 8.1 | |
| android | 8.1 |
Timeline
- Dec 2, 2024 CVE Published
- Dec 2, 2024 CVE Updated
- Dec 3, 2024 EPSS Score
- Dec 20, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 24, 2025 EPSS Score
- Feb 10, 2025 EPSS Score
- Feb 28, 2025 EPSS Score
- Mar 17, 2025 EPSS Score
- Apr 3, 2025 EPSS Score
- Apr 20, 2025 EPSS Score
- May 8, 2025 EPSS Score