|
|
Good to see CVE used to identify vulnerabilities: https://source.android.com/security/bulletin/2017-06-01#qualcomm-closed-source-components but there's little or no information about any of these vulnerabilities. Lots of RESERVED. This touches on the use of CVE for "internal" finds. There's value in having a public label, but the lack of even summary information (minimal CVE entry) is problematic. - Art