Lucene search

K
cveMitreCVE-2015-8306
HistoryJan 12, 2016 - 7:59 p.m.

CVE-2015-8306

2016-01-1219:59:09
CWE-119
mitre
web.nvd.nist.gov
25
buffer overflow
hifi driver
huawei p8
denial of service
execute arbitrary code

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.001

Percentile

41.4%

Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) or execute arbitrary code via an unspecified parameter.

Affected configurations

Nvd
Node
huaweip8_firmwareMatchgra-cl10
OR
huaweip8_firmwareMatchgra-cl100
OR
huaweip8_firmwareMatchgra-tl00
OR
huaweip8_firmwareMatchgra-ul10
OR
huaweip8_firmwareMatchgra-ul100
AND
huaweip8Match-
VendorProductVersionCPE
huaweip8_firmwaregra-cl10cpe:2.3:o:huawei:p8_firmware:gra-cl10:*:*:*:*:*:*:*
huaweip8_firmwaregra-cl100cpe:2.3:o:huawei:p8_firmware:gra-cl100:*:*:*:*:*:*:*
huaweip8_firmwaregra-tl00cpe:2.3:o:huawei:p8_firmware:gra-tl00:*:*:*:*:*:*:*
huaweip8_firmwaregra-ul10cpe:2.3:o:huawei:p8_firmware:gra-ul10:*:*:*:*:*:*:*
huaweip8_firmwaregra-ul100cpe:2.3:o:huawei:p8_firmware:gra-ul100:*:*:*:*:*:*:*
huaweip8-cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.001

Percentile

41.4%

Related for CVE-2015-8306