Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zhou Ye

Researcher from360 Vulpecker Team
#18900of 53,632
14.2Total CVSS
Vulnerabilities · 2
High
2
PT-2017-15518
7.1
2017-11-22
Huawei · Huawei P9 Plus · CVE-2017-2731
**Name of the Vulnerable Software and Affected Versions** Huawei P9 Plus versions prior to VIE-AL10C00B386 **Description** The issue affects the vibrator service, allowing an attacker to crash the system by tricking a user into installing a malicious application and sending a specific parameter to the smart phone vibrator service interface. **Recommendations** For versions prior to VIE-AL10C00B386, update to version VIE-AL10C00B386 or later to resolve the issue.
PT-2017-15521
7.1
2017-11-22
Huawei · P9 Plus · CVE-2017-2734
**Name of the Vulnerable Software and Affected Versions** P9 Plus smartphones with software versions earlier than VIE-AL10BC00B386 **Description** The issue allows an attacker to trick a user into installing a malicious application on the smartphone. This application can send a given parameter to a specific interface, causing a large number of memory allocations and resulting in the smartphone crashing due to memory exhaustion. **Recommendations** For P9 Plus smartphones with software versions earlier than VIE-AL10BC00B386, update to a version VIE-AL10BC00B386 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.