CVE-2015-9162

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12, SD 617, SD 650/52, SD 800, SD 808, and SD 810, in the function "Certificate_CreateWithBuffer" in the QSEE app TQS, in case of memory allocation failure, we free the memory and return the pointer without setting it to NULL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
qualcommsd_410_firmware
-
qualcommsd_412_firmware
-
qualcommsd_617_firmware
-
qualcommsd_650_firmware
-
qualcommsd_652_firmware
-
qualcommsd_800_firmware
-
qualcommsd_808_firmware
-
qualcommsd_810_firmware
-
𝑥
= Vulnerable software versions