Vulnerability Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 400, SD 800, SD 820, and SD 820A, lack of input validation in QSEE can cause potential buffer overflow.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9625 Firmware | - |
| Qualcomm | Mdm9625 | - |
| Qualcomm | Sd 400 Firmware | - |
| Qualcomm | Sd 400 | - |
| Qualcomm | Sd 800 Firmware | - |
| Qualcomm | Sd 800 | - |
| Qualcomm | Sd 820A Firmware | - |
| Qualcomm | Sd 820A | - |
| Qualcomm | Sd 820 Firmware | - |
| Qualcomm | Sd 820 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103671Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
- http://www.securityfocus.com/bid/103671Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
FAQ
What is CVE-2015-9112?
CVE-2015-9112 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 400, SD 800, SD 820, and SD 820A, lack of input validation in QSEE can ...
How severe is CVE-2015-9112?
CVE-2015-9112 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-9112?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Mdm9625 Firmware, Qualcomm Mdm9625, Qualcomm Sd 400 Firmware, Qualcomm Sd 400, Qualcomm Sd 800 Firmware.