CVE-2014-9799
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The makefile in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices omits the -fno-strict-overflow option to gcc, which might allow attackers to gain privileges via a crafted application that leverages incorrect compi...
CVE-2014-9798
- EPSS 0.05%
- Veröffentlicht 11.07.2016 01:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via ...
CVE-2014-9796
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the page size in the kernel header, which allows attackers to bypass intended access restrictions via a crafted boot image, ak...
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does not properly check for an integer overflow, which allows attackers to bypass intended access restrictions via crafted start and size values, aka Android...
CVE-2014-9793
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
platform/msm_shared/mmc.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices mishandles the power-on write-protect feature, which allows attackers to gain privileges via a crafted application, aka Android internal bug 2...
CVE-2014-9792
- EPSS 0.15%
- Veröffentlicht 11.07.2016 01:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769399 and ...
CVE-2014-9790
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/mmc/core/debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate pointers used in read and write operations, which allows attackers to gain privileges via a crafted application, aka ...
CVE-2014-9789
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) alloc and (2) free APIs in arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices do not validate parameters, which allows attackers to gain privileges via a crafted application, a...
CVE-2014-9788
- EPSS 0.06%
- Veröffentlicht 11.07.2016 01:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the voice drivers in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28573112 and Qualcomm internal bug CR5488...
CVE-2014-9787
- EPSS 0.07%
- Veröffentlicht 11.07.2016 01:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28571496 and Qualcomm internal bug CR...