CVE-2017-13321

In SensorService::isDataInjectionEnabled offrameworks/native/services/sensorservice/SensorService.cpp, there is apossible out of bounds read due to a missing bounds check. This could leadto local information disclosure with no additional execution privilegesneeded. User interaction is not needed for exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
google_androidCNA
---
---
CISA-ADPADP
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
googleandroid
8.0
googleandroid
8.1
𝑥
= Vulnerable software versions