CVE-2015-9183

EUVD-2015-9036
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12, SD 617, SD 650/52, SD 800, SD 808, and SD 810, in TQS QSEE application, while parsing "Set Certificates" command an integer overflow may result in buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Affected Products (NVD)
VendorProductVersion
qualcommsd_410_firmware
-
qualcommsd_412_firmware
-
qualcommsd_617_firmware
-
qualcommsd_652_firmware
-
qualcommsd_800_firmware
-
qualcommsd_808_firmware
-
qualcommsd_810_firmware
-
qualcommsd_650_firmware
-
𝑥
= Vulnerable software versions