10

CVE-2015-9147

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, SD 400, and SD 800, userspace-provided pointer arguments are not validated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm9625 Firmware Version -
   Qualcomm ≫ Mdm9625 Version -
Qualcomm ≫ Mdm9635m Firmware Version -
   Qualcomm ≫ Mdm9635m Version -
Qualcomm ≫ Sd 400 Firmware Version -
   Qualcomm ≫ Sd 400 Version -
Qualcomm ≫ Sd 800 Firmware Version -
   Qualcomm ≫ Sd 800 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://source.android.com/security/bulletin/2018-04-01
Vendor Advisory
http://www.securityfocus.com/bid/103671
Third Party Advisory
VDB Entry