10

CVE-2016-10442

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to arbitrary regions of memory, the user may utilize this vector to alter module executable code.

Data is provided by the National Vulnerability Database (NVD)
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommMsm8976 Firmware Version-
   QualcommMsm8976 Version-
QualcommMsm8937 Firmware Version-
   QualcommMsm8937 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
QualcommMsm8976 Firmware Version-
   QualcommMsm8976 Version-
QualcommMsm8952 Firmware Version-
   QualcommMsm8952 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.358
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.