10

CVE-2015-9212

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, lack of input validation while processing TZ_PR_CMD_SAVE_KEY command could lead to a buffer overread.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Msm8909w Firmware Version -
   Qualcomm ≫ Msm8909w Version -
Qualcomm ≫ Sd 210 Firmware Version -
   Qualcomm ≫ Sd 210 Version -
Qualcomm ≫ Sd 212 Firmware Version -
   Qualcomm ≫ Sd 212 Version -
Qualcomm ≫ Sd 205 Firmware Version -
   Qualcomm ≫ Sd 205 Version -
Qualcomm ≫ Sd 400 Firmware Version -
   Qualcomm ≫ Sd 400 Version -
Qualcomm ≫ Sd 410 Firmware Version -
   Qualcomm ≫ Sd 410 Version -
Qualcomm ≫ Sd 412 Firmware Version -
   Qualcomm ≫ Sd 412 Version -
Qualcomm ≫ Sd 800 Firmware Version -
   Qualcomm ≫ Sd 800 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.672
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://source.android.com/security/bulletin/2018-04-01
Vendor Advisory
http://www.securityfocus.com/bid/103671
Third Party Advisory
VDB Entry