CVE-2015-9185
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, in multiple Secure DEMUX functions (e.g., SDMX_open_session, SDMX_close_session, SDMX_set_session_cfg), when parameter validation fails, an error code is written into a response buffer, without checking that response buffer length (rsplen) passed from HLOS is large enough to hold the response. If the buffer is at the end of a non-secure page followed by secured memory page, this can cause a secure memory corruption.
En Android, antes del nivel de parche de seguridad del 2018-04-05 o antes en Qualcomm Snapdragon Automobile, Snapdragon Mobile y Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845 y SD 850, en múltiples funciones DEMUX (por ejemplo, SDMX_open_session, SDMX_close_session o SDMX_set_session_cfg), cuando la validación de parámetros fracasa, se escribe un código de error en un búfer de respuesta, sin comprobar que la longitud del búfer de respuesta (rsplen) pasado desde HLOS es lo suficientemente grande para contener la respuesta. Si el búfer está al final de una página no segura, seguida por una página de memoria segura, esto puede provocar una corrupción de memoria segura.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-16 CVE Reserved
- 2018-04-18 CVE Published
- 2023-09-09 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103671 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://source.android.com/security/bulletin/2018-04-01 | 2018-05-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qualcomm Search vendor "Qualcomm" | Mdm9206 Firmware Search vendor "Qualcomm" for product "Mdm9206 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9206 Search vendor "Qualcomm" for product "Mdm9206" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9650 Firmware Search vendor "Qualcomm" for product "Mdm9650 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9650 Search vendor "Qualcomm" for product "Mdm9650" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 210 Firmware Search vendor "Qualcomm" for product "Sd 210 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 210 Search vendor "Qualcomm" for product "Sd 210" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 212 Firmware Search vendor "Qualcomm" for product "Sd 212 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 212 Search vendor "Qualcomm" for product "Sd 212" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 205 Firmware Search vendor "Qualcomm" for product "Sd 205 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 205 Search vendor "Qualcomm" for product "Sd 205" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 410 Firmware Search vendor "Qualcomm" for product "Sd 410 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 410 Search vendor "Qualcomm" for product "Sd 410" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 412 Firmware Search vendor "Qualcomm" for product "Sd 412 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 412 Search vendor "Qualcomm" for product "Sd 412" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 425 Firmware Search vendor "Qualcomm" for product "Sd 425 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 425 Search vendor "Qualcomm" for product "Sd 425" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 430 Firmware Search vendor "Qualcomm" for product "Sd 430 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 430 Search vendor "Qualcomm" for product "Sd 430" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 450 Firmware Search vendor "Qualcomm" for product "Sd 450 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 450 Search vendor "Qualcomm" for product "Sd 450" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 615 Firmware Search vendor "Qualcomm" for product "Sd 615 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 615 Search vendor "Qualcomm" for product "Sd 615" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 616 Firmware Search vendor "Qualcomm" for product "Sd 616 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 616 Search vendor "Qualcomm" for product "Sd 616" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 415 Firmware Search vendor "Qualcomm" for product "Sd 415 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 415 Search vendor "Qualcomm" for product "Sd 415" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 617 Firmware Search vendor "Qualcomm" for product "Sd 617 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 617 Search vendor "Qualcomm" for product "Sd 617" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 625 Firmware Search vendor "Qualcomm" for product "Sd 625 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 625 Search vendor "Qualcomm" for product "Sd 625" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 650 Firmware Search vendor "Qualcomm" for product "Sd 650 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 650 Search vendor "Qualcomm" for product "Sd 650" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 652 Firmware Search vendor "Qualcomm" for product "Sd 652 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 652 Search vendor "Qualcomm" for product "Sd 652" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 800 Firmware Search vendor "Qualcomm" for product "Sd 800 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 800 Search vendor "Qualcomm" for product "Sd 800" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 808 Firmware Search vendor "Qualcomm" for product "Sd 808 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 808 Search vendor "Qualcomm" for product "Sd 808" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 810 Firmware Search vendor "Qualcomm" for product "Sd 810 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 810 Search vendor "Qualcomm" for product "Sd 810" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 820 Firmware Search vendor "Qualcomm" for product "Sd 820 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 820 Search vendor "Qualcomm" for product "Sd 820" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 835 Firmware Search vendor "Qualcomm" for product "Sd 835 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 835 Search vendor "Qualcomm" for product "Sd 835" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 845 Firmware Search vendor "Qualcomm" for product "Sd 845 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 845 Search vendor "Qualcomm" for product "Sd 845" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 600 Firmware Search vendor "Qualcomm" for product "Sd 600 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 600 Search vendor "Qualcomm" for product "Sd 600" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 850 Firmware Search vendor "Qualcomm" for product "Sd 850 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 850 Search vendor "Qualcomm" for product "Sd 850" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 820a Firmware Search vendor "Qualcomm" for product "Sd 820a Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 820a Search vendor "Qualcomm" for product "Sd 820a" | - | - |
Safe
|