Vulnerabilities > CVE-2017-18658 - NULL Pointer Dereference vulnerability in Google Android 6.0

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
google
CWE-476

Summary

An issue was discovered on Samsung mobile devices with M(6.0) software. The multiwindow_facade API allows attackers to cause a NullPointerException and system halt via an attempted screen touch of a non-existing display. The Samsung ID is SVE-2017-9383 (August 2017).

Vulnerable Configurations

Part Description Count
OS
Google
1

Common Weakness Enumeration (CWE)