CVE-2017-13261
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 7.4%
from disclosure to weapon0 days
Published on NVDApr 4
1st PoCMar 23
exploitation probability
7.4%top 6% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177292.
Affected products
Google Inc. · Androidpublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/44326unverifiedexploitdbwww.exploit-db.com/exploits/44327unverifiedcve_referencewww.exploit-db.com/exploits/44326/unverifiedcve_referencewww.exploit-db.com/exploits/44327/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.