peter bassill · operator
$ cve CVE-2018-10751 JSON

CVE-2018-10751 EXPLOIT

5.3
MEDIUM · CVSS 3.0 · EPSS 8.6% (pctl 95)

Patch early

A public exploit exists.

Description

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

Scoring

CVSS5.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS8.64% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploityes
Published2018-05-29
Last modified2026-06-17

Affected (1)

VendorProduct
samsungsamsung mobile

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD