CVE-2018-9412

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
References
Link Resource
https://source.android.com/security/bulletin/2018-07-01 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*

History

19 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-400

11 Dec 2024, 15:15

Type Values Removed Values Added
CWE CWE-770

05 Dec 2024, 21:15

Type Values Removed Values Added
CWE CWE-770

Information

Published : 2024-11-19 22:15

Updated : 2025-03-19 18:15


NVD link : CVE-2018-9412

Mitre link : CVE-2018-9412

CVE.ORG link : CVE-2018-9412


JSON object : View

Products Affected

google

  • android
CWE
NVD-CWE-noinfo CWE-400

Uncontrolled Resource Consumption