10
CVSSv2

CVE-2015-9199

Published: 18/04/2018 Updated: 09/05/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In Android prior to 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile IPQ4019, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 810, SD 820, and SD 820A, A non-secure region check is done while registering QSEE buffer address which is passed by HLOS but not while logging in the QSEE buffer, so corruption of dynamically protected secure region can occur if the non-secure buffer is changed between the time it's checked and when it's used.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm ipq4019 firmware -

qualcomm mdm9625 firmware -

qualcomm mdm9635m firmware -

qualcomm mdm9640 firmware -

qualcomm mdm9650 firmware -

qualcomm mdm9655 firmware -

qualcomm sd 210 firmware -

qualcomm sd 212 firmware -

qualcomm sd 205 firmware -

qualcomm sd 400 firmware -

qualcomm sd 410 firmware -

qualcomm sd 412 firmware -

qualcomm sd 615 firmware -

qualcomm sd 616 firmware -

qualcomm sd 415 firmware -

qualcomm sd 800 firmware -

qualcomm sd 808 firmware -

qualcomm sd 810 firmware -

qualcomm sd 820 firmware -

qualcomm sd 820a firmware -