Lucene search

K
cveQualcommCVE-2015-9169
HistoryApr 18, 2018 - 2:29 p.m.

CVE-2015-9169

2018-04-1814:29:05
CWE-200
qualcomm
web.nvd.nist.gov
28
android
qualcomm
snapdragon
mobile
wear
msm8909w
sd 210
sd 212
sd 205
sd 400
sd 410
sd 412
sd 615
sd 616
sd 415
sd 617
sd 650
sd 652
sd 800
sd 808
sd 810
buffer over-read
qsee
information leakage

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

43.1%

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, and SD 810, buffer over-read in QSEE app may cause confidential information to be leaked.

Affected configurations

Nvd
Node
qualcommmsm8909w_firmwareMatch-
AND
qualcommmsm8909wMatch-
Node
qualcommsd_210_firmwareMatch-
AND
qualcommsd_210Match-
Node
qualcommsd_212_firmwareMatch-
AND
qualcommsd_212Match-
Node
qualcommsd_205_firmwareMatch-
AND
qualcommsd_205Match-
Node
qualcommsd_400_firmwareMatch-
AND
qualcommsd_400Match-
Node
qualcommsd_410_firmwareMatch-
AND
qualcommsd_410Match-
Node
qualcommsd_412_firmwareMatch-
AND
qualcommsd_412Match-
Node
qualcommsd_615_firmwareMatch-
AND
qualcommsd_615Match-
Node
qualcommsd_616_firmwareMatch-
AND
qualcommsd_616Match-
Node
qualcommsd_415_firmwareMatch-
AND
qualcommsd_415Match-
Node
qualcommsd_617_firmwareMatch-
AND
qualcommsd_617Match-
Node
qualcommsd_650_firmwareMatch-
AND
qualcommsd_650Match-
Node
qualcommsd_652_firmwareMatch-
AND
qualcommsd_652Match-
Node
qualcommsd_800_firmwareMatch-
AND
qualcommsd_800Match-
Node
qualcommsd_808_firmwareMatch-
AND
qualcommsd_808Match-
Node
qualcommsd_810_firmwareMatch-
AND
qualcommsd_810Match-
VendorProductVersionCPE
qualcommmsm8909w_firmware-cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*
qualcommmsm8909w-cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*
qualcommsd_210_firmware-cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*
qualcommsd_210-cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*
qualcommsd_212_firmware-cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*
qualcommsd_212-cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*
qualcommsd_205_firmware-cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*
qualcommsd_205-cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:*
qualcommsd_400_firmware-cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*
qualcommsd_400-cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 321

CNA Affected

[
  {
    "product": "Snapdragon Mobile, Snapdragon Wear",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, SD 810"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

43.1%

Related for CVE-2015-9169