10

CVE-2015-9148

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 400, SD 425, SD 430, SD 450, SD 600, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, in the Diag User-PD command registration function, a length variable used during buffer allocation is not checked, so if it is very large, an integer overflow followed by a buffer overflow occurs.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMdm9625 Firmware Version-
   QualcommMdm9625 Version-
QualcommMdm9635m Firmware Version-
   QualcommMdm9635m Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommMdm9645 Firmware Version-
   QualcommMdm9645 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMdm9655 Firmware Version-
   QualcommMdm9655 Version-
QualcommSd 400 Firmware Version-
   QualcommSd 400 Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommSd 430 Firmware Version-
   QualcommSd 430 Version-
QualcommSd 450 Firmware Version-
   QualcommSd 450 Version-
QualcommSd 600 Firmware Version-
   QualcommSd 600 Version-
QualcommSd 617 Firmware Version-
   QualcommSd 617 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommSd 650 Firmware Version-
   QualcommSd 650 Version-
QualcommSd 652 Firmware Version-
   QualcommSd 652 Version-
QualcommSd 800 Firmware Version-
   QualcommSd 800 Version-
QualcommSd 808 Firmware Version-
   QualcommSd 808 Version-
QualcommSd 810 Firmware Version-
   QualcommSd 810 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSd 835 Firmware Version-
   QualcommSd 835 Version-
QualcommSd 845 Firmware Version-
   QualcommSd 845 Version-
QualcommSdx20 Firmware Version-
   QualcommSdx20 Version-
QualcommSd 850 Firmware Version-
   QualcommSd 850 Version-
QualcommSd 820a Firmware Version-
   QualcommSd 820a Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.434
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.