CVE-2018-10751

UnknownEPSS 8.75%

Last modified

CVE-2018-10751 is a vulnerability of currently unknown severity. A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. EPSS estimates a 8.75% chance of exploitation in the next 30 days.

Description

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

Metrics

EPSS Probability
8.75%

94.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SamsungSamsung Mobile6.0
SamsungSamsung Mobile7.0
SamsungSamsung Mobile7.1
SamsungSamsung Mobile7.1.1
SamsungSamsung Mobile7.1.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-10751?
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
How severe is CVE-2018-10751?
Severity scoring for CVE-2018-10751 is pending analysis. The EPSS model estimates a 8.75% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10751?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-10751?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST