VULNERABILITY INTELLIGENCE
CVE-2018-12006
CVSS score5.5 MEDIUM
EPSS probability0.14%
CISA KEVNot currently listed
Published2019-02-11
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized padding present in display function.
Weakness classification
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Primary references
- product-security@qualcomm.com — Patch, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Third Party Advisory