{"api_version":"1","generated_at":"2026-07-23T11:34:52+00:00","cve":"CVE-2017-11027","urls":{"html":"https://cve.report/CVE-2017-11027","api":"https://cve.report/api/cve/CVE-2017-11027.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-11027","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-11027"},"summary":{"title":"CVE-2017-11027","description":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability.","state":"PUBLISHED","assigner":"qualcomm","published_at":"2017-11-16 22:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-20","Information Exposure in Boot"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://source.android.com/security/bulletin/pixel/2017-11-01","name":"https://source.android.com/security/bulletin/pixel/2017-11-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Pixel&hairsp;/&hairsp;Nexus Security Bulletin—November 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-11027","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11027","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Qualcomm, Inc.","product":"Android for MSM, Firefox OS for MSM, QRD Android","version":"affected All Android releases from CAF using the Linux kernel","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"11027","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"11027","cve":"CVE-2017-11027","epss":"0.000160000","percentile":"0.039380000","score_date":"2026-05-13","updated_at":"2026-05-14 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:57:57.095Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/pixel/2017-11-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Android for MSM, Firefox OS for MSM, QRD Android","vendor":"Qualcomm, Inc.","versions":[{"status":"affected","version":"All Android releases from CAF using the Linux kernel"}]}],"datePublic":"2017-11-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability."}],"problemTypes":[{"descriptions":[{"description":"Information Exposure in Boot","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-16T21:57:01.000Z","orgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","shortName":"qualcomm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/pixel/2017-11-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2017-11-01T00:00:00","ID":"CVE-2017-11027","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Exposure in Boot"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/pixel/2017-11-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/pixel/2017-11-01"}]}}}},"cveMetadata":{"assignerOrgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","assignerShortName":"qualcomm","cveId":"CVE-2017-11027","datePublished":"2017-11-16T22:00:00.000Z","dateReserved":"2017-07-07T00:00:00.000Z","dateUpdated":"2024-09-16T23:11:44.476Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-16 22:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-20","Information Exposure in Boot"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"11027","Ordinal":"1","Title":"CVE-2017-11027","CVE":"CVE-2017-11027","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"11027","Ordinal":"1","NoteData":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability.","Type":"Description","Title":"CVE-2017-11027"},{"CveYear":"2017","CveId":"11027","Ordinal":"2","NoteData":"2017-11-16","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"11027","Ordinal":"3","NoteData":"2017-11-16","Type":"Other","Title":"Modified"}]}}}