CVE-2017-14910
https://notcve.org/view.php?id=CVE-2017-14910
In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835, and SD 845, a buffer overread is possible if there are no newlines in an input file. En Snapdragon Automobile, Snapdragon IoT y Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835 y SD 845, es posible una sobrelectura de búfer si no hay nuevas líneas en un archivo de entradas. • https://source.android.com/security/bulletin/2018-02-01 • CWE-125: Out-of-bounds Read •
CVE-2015-9222 – RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
https://notcve.org/view.php?id=CVE-2015-9222
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, processing erroneous bitstreams may result in a HW freeze. FW should detect the HW freeze based on watchdog timer, but because the watchdog timer is not enabled, an infinite loop occurs, resulting in a device freeze. En Android, antes del nivel de parche de seguridad del 2018-04-05 o antes en Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660 y Snapdragon_High_Med_2016, el procesamiento de bitstreams erróneos puede resultar en un bloqueo del hardware. El firmware debería detectar que el hardware se ha bloqueado en base al temporizador guardián pero, debido a que este temporizador no está habilitado, ocurre un bucle infinito que desemboca en un bloqueo del dispositivo. • https://www.exploit-db.com/exploits/39739 http://www.securityfocus.com/bid/103671 https://source.android.com/security/bulletin/2018-04-01 • CWE-399: Resource Management Errors •