CVE-2015-9221NULL Pointer Dereference in INC Snapdragon Mobile

Severity
9.8CRITICALNVD
EPSS
0.2%
top 61.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 14

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers passed by secure apps could lead to an untrusted pointer dereference.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobileSD 400, SD 800, SD 810

🔴Vulnerability Details

1
GHSA
GHSA-j8wg-pghx-wr4x: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers2022-05-14

📋Vendor Advisories

1
Android
CVE-2015-9221: Closed-source component2018-04-01