{"api_version":"1","generated_at":"2026-07-23T08:28:41+00:00","cve":"CVE-2018-5887","urls":{"html":"https://cve.report/CVE-2018-5887","api":"https://cve.report/api/cve/CVE-2018-5887.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-5887","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-5887"},"summary":{"title":"CVE-2018-5887","description":"While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2018-07-06 17:29:00","updated_at":"2018-08-27 18:09:00"},"problem_types":["CWE-125"],"metrics":[],"references":[{"url":"https://source.codeaurora.org/quic/la/abl/tianocore/edk2/commit/?id=c8415f6f2271008aef5056689950236df627d9b1","name":"https://source.codeaurora.org/quic/la/abl/tianocore/edk2/commit/?id=c8415f6f2271008aef5056689950236df627d9b1","refsource":"CONFIRM","tags":["Patch"],"title":"abl/tianocore/edk2 - Unnamed repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://source.android.com/security/bulletin/pixel/2018-06-01#qualcomm-components","name":"https://source.android.com/security/bulletin/pixel/2018-06-01#qualcomm-components","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Pixel&hairsp;/&hairsp;Nexus Security Bulletin—June 2018","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-5887","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-5887","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"5887","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"5887","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2018-06-05T00:00:00","ID":"CVE-2018-5887","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Validation of Array Index in Boot"}]}]},"references":{"reference_data":[{"name":"https://source.codeaurora.org/quic/la/abl/tianocore/edk2/commit/?id=c8415f6f2271008aef5056689950236df627d9b1","refsource":"CONFIRM","url":"https://source.codeaurora.org/quic/la/abl/tianocore/edk2/commit/?id=c8415f6f2271008aef5056689950236df627d9b1"},{"name":"https://source.android.com/security/bulletin/pixel/2018-06-01#qualcomm-components","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/pixel/2018-06-01#qualcomm-components"}]}},"nvd":{"publishedDate":"2018-07-06 17:29:00","lastModifiedDate":"2018-08-27 18:09:00","problem_types":["CWE-125"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"5887","Ordinal":"121890","Title":"CVE-2018-5887","CVE":"CVE-2018-5887","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"5887","Ordinal":"1","NoteData":"While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"5887","Ordinal":"2","NoteData":"2018-07-06","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"5887","Ordinal":"3","NoteData":"2018-07-06","Type":"Other","Title":"Modified"}]}}}