CVE-2015-9220

EUVD-2015-9073
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, and SDX20, integer overflow occurs when the size of the firmware section is incorrectly encoded in the firmware image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommipq4019_firmware
-
qualcommipq8064_firmware
-
qualcommqca4531_firmware
-
qualcommmdm9640_firmware
-
qualcommqca6174a_firmware
-
qualcommmdm9650_firmware
-
qualcommqca6574au_firmware
-
qualcommqca6584_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommqca6584au_firmware
-
qualcommqca9377_firmware
-
qualcommqca9378_firmware
-
qualcommsd_425_firmware
-
qualcommqca9379_firmware
-
qualcommqca9558_firmware
-
qualcommqca9880_firmware
-
qualcommqca9886_firmware
-
qualcommqca9980_firmware
-
qualcommsd_625_firmware
-
qualcommsd_810_firmware
-
qualcommsd_820_firmware
-
qualcommsdx20_firmware
-
𝑥
= Vulnerable software versions