CVE-2018-10751 EXPLOIT
5.3
MEDIUM · CVSS 3.0 · EPSS 8.6% (pctl 95)
Patch early
A public exploit exists.
Description
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
Scoring
| CVSS | 5.3 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H |
| EPSS | 8.64% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-05-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| samsung | samsung mobile |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing | 2018-05-23 |
References
- http://packetstormsecurity.com/files/147841/Samsung-Galaxy-S7-Edge-OMACP-WbXml-String-Extension-Processing-Overflow.html
- https://security.samsungmobile.com/securityUpdate.smsb
- https://www.exploit-db.com/exploits/44724/
- http://packetstormsecurity.com/files/147841/Samsung-Galaxy-S7-Edge-OMACP-WbXml-String-Extension-Processing-Overflow.html
- https://security.samsungmobile.com/securityUpdate.smsb
- https://www.exploit-db.com/exploits/44724/
→ the Explorer · watch your stack · NVD