CVE-2014-9981Improper Restriction of Operations within the Bounds of a Memory Buffer in INC Snapdragon Mobile

Severity
9.8CRITICALNVD
EPSS
0.3%
top 47.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateMay 14

Description

In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobileMDM9625, MDM9635M, SD 400, SD 410/12, SD 615/16/SD 415

🔴Vulnerability Details

1
GHSA
GHSA-fgxg-v6h6-59m2: In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot2022-05-14

📋Vendor Advisories

1
Android
CVE-2014-9981: Closed-source component2018-04-01

📄Research Papers

1
arXiv
An Empirical Study of Android Security Bulletins in Different Vendors2020-02-22