Mediatek Preloader Vulnerable to Out-of-Bounds Reads and Writes
CVE-2018-9371

6.4MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2018-9371?

The Mediatek Preloader contains vulnerabilities related to out of bounds reads and writes, stemming from an exposed interface that permits arbitrary peripheral memory mapping without adequate blacklisting or whitelisting. This security flaw can lead to local elevation of privilege if an attacker has physical access to the affected device. Notably, the exploitation of this vulnerability requires user interaction, emphasizing the importance of physical security and user awareness to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android SoCVersion

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.