{"api_version":"1","generated_at":"2026-07-23T06:33:42+00:00","cve":"CVE-2017-11087","urls":{"html":"https://cve.report/CVE-2017-11087","api":"https://cve.report/api/cve/CVE-2017-11087.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-11087","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-11087"},"summary":{"title":"CVE-2017-11087","description":"libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the \"filled length\", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2018-03-30 21:29:00","updated_at":"2018-04-25 15:00:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/103669","name":"103669","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Qualcomm Component CVE-2017-11087 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://source.android.com/security/bulletin/pixel/2018-02-01","name":"https://source.android.com/security/bulletin/pixel/2018-02-01","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Pixel&hairsp;/&hairsp;Nexus Security Bulletin—February 2018  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-11087","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11087","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"11087","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"11087","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2018-03-26T00:00:00","ID":"CVE-2017-11087","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the \"filled length\", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Buffer Over-read in Video"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/pixel/2018-02-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/pixel/2018-02-01"},{"name":"103669","refsource":"BID","url":"http://www.securityfocus.com/bid/103669"}]}},"nvd":{"publishedDate":"2018-03-30 21:29:00","lastModifiedDate":"2018-04-25 15:00:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"11087","Ordinal":"108131","Title":"CVE-2017-11087","CVE":"CVE-2017-11087","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"11087","Ordinal":"1","NoteData":"libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the \"filled length\", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"11087","Ordinal":"2","NoteData":"2018-03-30","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"11087","Ordinal":"3","NoteData":"2018-04-06","Type":"Other","Title":"Modified"}]}}}