{"api_version":"1","generated_at":"2026-07-23T12:43:29+00:00","cve":"CVE-2017-11059","urls":{"html":"https://cve.report/CVE-2017-11059","api":"https://cve.report/api/cve/CVE-2017-11059.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-11059","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-11059"},"summary":{"title":"CVE-2017-11059","description":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2017-10-10 20:29:00","updated_at":"2017-10-19 17:59:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/101160","name":"101160","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://source.android.com/security/bulletin/pixel/2017-10-01","name":"https://source.android.com/security/bulletin/pixel/2017-10-01","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Pixel&hairsp;/&hairsp;Nexus Security Bulletin—October 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-11059","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11059","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"11059","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11059","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2017-10-02T00:00:00","ID":"CVE-2017-11059","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/pixel/2017-10-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/pixel/2017-10-01"},{"name":"101160","refsource":"BID","url":"http://www.securityfocus.com/bid/101160"}]}},"nvd":{"publishedDate":"2017-10-10 20:29:00","lastModifiedDate":"2017-10-19 17:59:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"11059","Ordinal":"108103","Title":"CVE-2017-11059","CVE":"CVE-2017-11059","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"11059","Ordinal":"1","NoteData":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"11059","Ordinal":"2","NoteData":"2017-10-10","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"11059","Ordinal":"3","NoteData":"2017-10-11","Type":"Other","Title":"Modified"}]}}}