Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-9998


In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 808, SD 810, SD 820, and SDX20, while processing firmware image signature, the internal buffer may overflow if the firmware signature size is large.


Published

2018-04-18T14:29:02.480

Last Modified

2024-11-21T02:22:09.610

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm mdm9206_firmware - Yes
Hardware qualcomm mdm9206 - No
Operating System qualcomm mdm9607_firmware - Yes
Hardware qualcomm mdm9607 - No
Operating System qualcomm ipq4019_firmware - Yes
Hardware qualcomm ipq4019 - No
Operating System qualcomm ipq8064_firmware - Yes
Hardware qualcomm ipq8064 - No
Operating System qualcomm mdm9635m_firmware - Yes
Hardware qualcomm mdm9635m - No
Operating System qualcomm mdm9640_firmware - Yes
Hardware qualcomm mdm9640 - No
Operating System qualcomm mdm9645_firmware - Yes
Hardware qualcomm mdm9645 - No
Operating System qualcomm mdm9650_firmware - Yes
Hardware qualcomm mdm9650 - No
Operating System qualcomm qca4531_firmware - Yes
Hardware qualcomm qca4531 - No
Operating System qualcomm qca6174a_firmware - Yes
Hardware qualcomm qca6174a - No
Operating System qualcomm sd_210_firmware - Yes
Hardware qualcomm sd_210 - No
Operating System qualcomm sd_212_firmware - Yes
Hardware qualcomm sd_212 - No
Operating System qualcomm sd_205_firmware - Yes
Hardware qualcomm sd_205 - No
Operating System qualcomm qca6574au_firmware - Yes
Hardware qualcomm qca6574au - No
Operating System qualcomm qca6584_firmware - Yes
Hardware qualcomm qca6584 - No
Operating System qualcomm qca6584au_firmware - Yes
Hardware qualcomm qca6584au - No
Operating System qualcomm sd_425_firmware - Yes
Hardware qualcomm sd_425 - No
Operating System qualcomm qca9377_firmware - Yes
Hardware qualcomm qca9377 - No
Operating System qualcomm qca9378_firmware - Yes
Hardware qualcomm qca9378 - No
Operating System qualcomm qca9379_firmware - Yes
Hardware qualcomm qca9379 - No
Operating System qualcomm qca9558_firmware - Yes
Hardware qualcomm qca9558 - No
Operating System qualcomm qca9880_firmware - Yes
Hardware qualcomm qca9880 - No
Operating System qualcomm qca9886_firmware - Yes
Hardware qualcomm qca9886 - No
Operating System qualcomm sd_625_firmware - Yes
Hardware qualcomm sd_625 - No
Operating System qualcomm qca9980_firmware - Yes
Hardware qualcomm qca9980 - No
Operating System qualcomm sd_808_firmware - Yes
Hardware qualcomm sd_808 - No
Operating System qualcomm sd_810_firmware - Yes
Hardware qualcomm sd_810 - No
Operating System qualcomm sd_820_firmware - Yes
Hardware qualcomm sd_820 - No
Operating System qualcomm sdx20_firmware - Yes
Hardware qualcomm sdx20 - No

References