Lucene search

K
cveMitreCVE-2015-8682
HistoryApr 13, 2016 - 2:59 p.m.

CVE-2015-8682

2016-04-1314:59:04
CWE-20
mitre
web.nvd.nist.gov
26
cve-2015-8682
video0 driver
huawei p8
mate s
smartphones
sensitive information
denial of service
system crash

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:N/A:C

CVSS3

6.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

27.4%

The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to obtain sensitive information from stack memory or cause a denial of service (system crash) via a crafted application, which triggers an invalid memory access.

Affected configurations

Nvd
Node
huaweimate_sMatch-
AND
huaweimate_s_firmwareRangecrr-cl00c92b153
OR
huaweimate_s_firmwareRangecrr-tl00c01b153sp01
OR
huaweimate_s_firmwareRangecrr-ul00c00b153
Node
huaweip8Match-
AND
huaweip8_firmwareRangegra-cl00c92b230
OR
huaweip8_firmwareRangegra-cl10c92b230
OR
huaweip8_firmwareRangegra-tl00c01b230
OR
huaweip8_firmwareRangegra-ul00c00b230
OR
huaweip8_firmwareRangegra-ul10c00b230
VendorProductVersionCPE
huaweimate_s-cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
huaweimate_s_firmware*cpe:2.3:a:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
huaweip8-cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
huaweip8_firmware*cpe:2.3:a:huawei:p8_firmware:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:N/A:C

CVSS3

6.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

27.4%

Related for CVE-2015-8682