CVE-2017-15347
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can riggers access memory after free it. A local attacker may exploit this vulnerability to cause the mobile phone to crash.
Los teléfonos móviles Huawei Mate 9 Pro con versiones de software anteriores a LON-AL00BC00B235 tienen una vulnerabilidad de uso de memoria previamente liberada (UAF). Un atacante engaña a un usuario para que instale una aplicación maliciosa que desencadene un acceso a la memoria tras liberarla. Un atacante local podría explotar esta vulnerabilidad para provocar que el teléfono móvil se cierre inesperadamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-14 CVE Reserved
- 2018-02-15 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-phone-en | 2018-02-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 9 Pro Firmware Search vendor "Huawei" for product "Mate 9 Pro Firmware" | lon-al00bc00b235 Search vendor "Huawei" for product "Mate 9 Pro Firmware" and version "lon-al00bc00b235" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 9 Pro Search vendor "Huawei" for product "Mate 9 Pro" | - | - |
Safe
|