CVE-2015-9146

EUVD-2015-8999
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, and SDX20, when QDI read, write, or ioctl are called, the passed-in pointer is not properly validated before accessing it for the delayed response.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9625_firmware
-
qualcommmdm9635m_firmware
-
qualcommmdm9650_firmware
-
qualcommmdm9655_firmware
-
qualcommsd_400_firmware
-
qualcommsd_800_firmware
-
qualcommsd_835_firmware
-
qualcommsd_845_firmware
-
qualcommsdx20_firmware
-
qualcommsd_850_firmware
-
𝑥
= Vulnerable software versions