CVE-2015-9220

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, and SDX20, integer overflow occurs when the size of the firmware section is incorrectly encoded in the firmware image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommipq4019_firmware
-
qualcommipq8064_firmware
-
qualcommqca4531_firmware
-
qualcommmdm9640_firmware
-
qualcommqca6174a_firmware
-
qualcommmdm9650_firmware
-
qualcommqca6574au_firmware
-
qualcommqca6584_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommqca6584au_firmware
-
qualcommqca9377_firmware
-
qualcommqca9378_firmware
-
qualcommsd_425_firmware
-
qualcommqca9379_firmware
-
qualcommqca9558_firmware
-
qualcommqca9880_firmware
-
qualcommqca9886_firmware
-
qualcommqca9980_firmware
-
qualcommsd_625_firmware
-
qualcommsd_810_firmware
-
qualcommsd_820_firmware
-
qualcommsdx20_firmware
-
𝑥
= Vulnerable software versions