CVE-2018-11816: Use After Free in Video

Published Sep 4, 2018
·
Updated

Crafted Binder Request Causes Heap UAF in MediaServer

Affected Software

29 affected components
Google Android
All of the following
Qualcomm 9206 Lte Modem Firmware
Qualcomm 9206 Lte Modem
All of the following
Qualcomm Apq8016 Firmware
Qualcomm Apq8016
All of the following
Qualcomm Apq8017 Firmware
Qualcomm Apq8017
All of the following
Qualcomm Apq8039 Firmware
Qualcomm Apq8039
All of the following
Qualcomm Apq8052 Firmware
Qualcomm Apq8052
All of the following
Qualcomm Apq8056 Firmware
Qualcomm Apq8056
All of the following
Qualcomm Apq8076 Firmware
Qualcomm Apq8076
All of the following
Qualcomm Aqt1000 Firmware
Qualcomm Aqt1000
All of the following
Qualcomm Ar6003 Firmware
Qualcomm Ar6003
All of the following
Qualcomm Sd660 Firmware
Qualcomm Sd660
All of the following
Qualcomm Sd670 Firmware
Qualcomm Sd670
All of the following
Qualcomm Sd820 Firmware
Qualcomm Sd820
All of the following
Qualcomm Sd821 Firmware
Qualcomm Sd821
All of the following
Qualcomm Sd835 Firmware
Qualcomm Sd835

Event History

Sep 4, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 26, 2024
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-11816?

CVE-2018-11816 has a high severity level due to the potential for remote code execution vulnerabilities.

2

How do I fix CVE-2018-11816?

To fix CVE-2018-11816, ensure your device's firmware is updated to the latest version provided by the manufacturer.

3

Which platforms are affected by CVE-2018-11816?

CVE-2018-11816 affects various versions of Android and specific Qualcomm firmware products.

4

Can CVE-2018-11816 be exploited remotely?

Yes, CVE-2018-11816 can potentially be exploited remotely if the conditions are met.

5

What is the impact of CVE-2018-11816?

The impact of CVE-2018-11816 includes the possibility of arbitrary code execution which can lead to further compromise of the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203