CVE-2014-9902
published 2016-08-05CVE-2014-9902: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.52%
83.1th percentile
Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 6.0.1 | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2014-9902: Android Security Bulletin 2016-08-01
CVE: CVE-2014-9902
Severity: CRITICAL
References: A-28668638
QC-CR#553937
QC-CR#553941
vendor_android·2016-08-01·CVSS 9.8
CVE-2014-9902 [CRITICAL] CVE-2014-9902: Android Security Bulletin 2016-08-01
CVE: CVE-2014-9902
Severity: CRITICAL
References: A-28668638
QC-CR#553937
QC-CR#553941
Android Security Bulletin 2016-08-01
CVE: CVE-2014-9902
Severity: CRITICAL
References: A-28668638
QC-CR#553937
QC-CR#553941
GHSA
GHSA-7w58-xjhm-qqxq: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f
ghsa_unreviewed·2022-05-17
CVE-2014-9902 [CRITICAL] CWE-119 GHSA-7w58-xjhm-qqxq: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f
Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.
OSV
CVE-2014-9902: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f
osv·2016-08-05·CVSS 9.8
CVE-2014-9902 [CRITICAL] CVE-2014-9902: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f
Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.securityfocus.com/bid/92223https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima/commit/?id=3b1c44a3a7129dc25abe2c23543f6f66c59e8f50http://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.securityfocus.com/bid/92223https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/prima/commit/?id=3b1c44a3a7129dc25abe2c23543f6f66c59e8f50
2016-08-05
Published