CVE-2017-15859: Google Android
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE_DECR_DB contains fewer than 1 byte, in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-11 a buffer overrun occurs.
Affected products
- Google Android: affected versions not specified
Published 2018-03-30. Last modified 2026-06-17.