10

CVE-2015-9220

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, and SDX20, integer overflow occurs when the size of the firmware section is incorrectly encoded in the firmware image.

Data is provided by the National Vulnerability Database (NVD)
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommIpq4019 Firmware Version-
   QualcommIpq4019 Version-
QualcommIpq8064 Firmware Version-
   QualcommIpq8064 Version-
QualcommQca4531 Firmware Version-
   QualcommQca4531 Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6584 Firmware Version-
   QualcommQca6584 Version-
QualcommSd 210 Firmware Version-
   QualcommSd 210 Version-
QualcommSd 212 Firmware Version-
   QualcommSd 212 Version-
QualcommSd 205 Firmware Version-
   QualcommSd 205 Version-
QualcommQca6584au Firmware Version-
   QualcommQca6584au Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommQca9378 Firmware Version-
   QualcommQca9378 Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommQca9379 Firmware Version-
   QualcommQca9379 Version-
QualcommQca9558 Firmware Version-
   QualcommQca9558 Version-
QualcommQca9880 Firmware Version-
   QualcommQca9880 Version-
QualcommQca9886 Firmware Version-
   QualcommQca9886 Version-
QualcommQca9980 Firmware Version-
   QualcommQca9980 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommSd 810 Firmware Version-
   QualcommSd 810 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSdx20 Firmware Version-
   QualcommSdx20 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.414
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.