Sign in
CVE-2015-9146
CVE-2015-9146
Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, and SDX20, when QDI read, write, or ioctl are called, the passed-in pointer is not properly validated before accessing it for the delayed response.
Impact
CVSS v3 : 9.8 CRITICAL
CVSS v2 : 10 HIGH
Type
CWE-20
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:C/I:C/A:C
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://www.securityfocus.com/bid/103671
https://source.android.com/security/bulletin/2018-04-01
FAQ
Terms of service
Privacy policy