{"api_version":"1","generated_at":"2026-07-23T09:29:36+00:00","cve":"CVE-2017-11028","urls":{"html":"https://cve.report/CVE-2017-11028","api":"https://cve.report/api/cve/CVE-2017-11028.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-11028","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-11028"},"summary":{"title":"CVE-2017-11028","description":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data().","state":"PUBLISHED","assigner":"qualcomm","published_at":"2017-11-16 22:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","Information Exposure in Camera"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://source.android.com/security/bulletin/2017-11-01","name":"https://source.android.com/security/bulletin/2017-11-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Android Security Bulletin—November 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/101774","name":"http://www.securityfocus.com/bid/101774","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Qualcomm Components Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-11028","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11028","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Qualcomm, Inc.","product":"Android for MSM, Firefox OS for MSM, QRD Android","version":"affected All Android releases from CAF using the Linux kernel","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"11028","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"11028","cve":"CVE-2017-11028","epss":"0.001110000","percentile":"0.290840000","score_date":"2026-05-13","updated_at":"2026-05-14 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:57:57.366Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"101774","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/101774"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/2017-11-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Android for MSM, Firefox OS for MSM, QRD Android","vendor":"Qualcomm, Inc.","versions":[{"status":"affected","version":"All Android releases from CAF using the Linux kernel"}]}],"datePublic":"2017-11-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data()."}],"problemTypes":[{"descriptions":[{"description":"Information Exposure in Camera","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-17T10:57:01.000Z","orgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","shortName":"qualcomm"},"references":[{"name":"101774","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/101774"},{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/2017-11-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2017-11-01T00:00:00","ID":"CVE-2017-11028","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data()."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Exposure in Camera"}]}]},"references":{"reference_data":[{"name":"101774","refsource":"BID","url":"http://www.securityfocus.com/bid/101774"},{"name":"https://source.android.com/security/bulletin/2017-11-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2017-11-01"}]}}}},"cveMetadata":{"assignerOrgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","assignerShortName":"qualcomm","cveId":"CVE-2017-11028","datePublished":"2017-11-16T22:00:00.000Z","dateReserved":"2017-07-07T00:00:00.000Z","dateUpdated":"2024-09-17T01:01:40.029Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-16 22:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","Information Exposure in Camera"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"11028","Ordinal":"1","Title":"CVE-2017-11028","CVE":"CVE-2017-11028","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"11028","Ordinal":"1","NoteData":"In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data().","Type":"Description","Title":"CVE-2017-11028"},{"CveYear":"2017","CveId":"11028","Ordinal":"2","NoteData":"2017-11-16","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"11028","Ordinal":"3","NoteData":"2017-11-17","Type":"Other","Title":"Modified"}]}}}