CVE-2014-10052

EUVD-2014-1124
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 600, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 810, SD 835, and SDX20, the reserved memory of TZ subsystem (like TZ apps and some PIL image subsystem) is not cleared after being used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommfsm9055_firmware
-
qualcommmdm9625_firmware
-
qualcommmdm9635m_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9645_firmware
-
qualcommmdm9650_firmware
-
qualcommmdm9655_firmware
-
qualcommmsm8909w_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommsd_400_firmware
-
qualcommsd_410_firmware
-
qualcommsd_412_firmware
-
qualcommipq4019_firmware
-
qualcommsd_615_firmware
-
qualcommsd_616_firmware
-
qualcommsd_415_firmware
-
qualcommsd_617_firmware
-
qualcommsd_650_firmware
-
qualcommsd_652_firmware
-
qualcommsd_800_firmware
-
qualcommsd_808_firmware
-
qualcommsd_810_firmware
-
qualcommsd_835_firmware
-
qualcommsdx20_firmware
-
𝑥
= Vulnerable software versions