10

CVE-2014-9998

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 808, SD 810, SD 820, and SDX20, while processing firmware image signature, the internal buffer may overflow if the firmware signature size is large.

Data is provided by the National Vulnerability Database (NVD)
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommIpq4019 Firmware Version-
   QualcommIpq4019 Version-
QualcommIpq8064 Firmware Version-
   QualcommIpq8064 Version-
QualcommMdm9635m Firmware Version-
   QualcommMdm9635m Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommMdm9645 Firmware Version-
   QualcommMdm9645 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommQca4531 Firmware Version-
   QualcommQca4531 Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommSd 210 Firmware Version-
   QualcommSd 210 Version-
QualcommSd 212 Firmware Version-
   QualcommSd 212 Version-
QualcommSd 205 Firmware Version-
   QualcommSd 205 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6584 Firmware Version-
   QualcommQca6584 Version-
QualcommQca6584au Firmware Version-
   QualcommQca6584au Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommQca9378 Firmware Version-
   QualcommQca9378 Version-
QualcommQca9379 Firmware Version-
   QualcommQca9379 Version-
QualcommQca9558 Firmware Version-
   QualcommQca9558 Version-
QualcommQca9880 Firmware Version-
   QualcommQca9880 Version-
QualcommQca9886 Firmware Version-
   QualcommQca9886 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommQca9980 Firmware Version-
   QualcommQca9980 Version-
QualcommSd 808 Firmware Version-
   QualcommSd 808 Version-
QualcommSd 810 Firmware Version-
   QualcommSd 810 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSdx20 Firmware Version-
   QualcommSdx20 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.31% 0.513
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.