Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2015-9166 (GCVE-0-2015-9166)
Vulnerability from cvelistv5 – Published: 2018-04-18 14:00 – Updated: 2024-09-16 18:44- Improper Access Control in Core.
| URL | Tags | |||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Qualcomm, Inc. | Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear |
Affected:
IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T08:43:41.034Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"name": "103671",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/103671"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear",
"vendor": "Qualcomm, Inc.",
"versions": [
{
"status": "affected",
"version": "IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850"
}
]
}
],
"datePublic": "2018-04-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Improper Access Control in Core.",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2018-04-19T09:57:01.000Z",
"orgId": "2cfc7d3e-20d3-47ac-8db7-1b7285aff15f",
"shortName": "qualcomm"
},
"references": [
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"name": "103671",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/103671"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "product-security@qualcomm.com",
"DATE_PUBLIC": "2018-04-02T00:00:00",
"ID": "CVE-2015-9166",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear",
"version": {
"version_data": [
{
"version_value": "IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850"
}
]
}
}
]
},
"vendor_name": "Qualcomm, Inc."
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Access Control in Core."
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://source.android.com/security/bulletin/2018-04-01",
"refsource": "CONFIRM",
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"name": "103671",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/103671"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "2cfc7d3e-20d3-47ac-8db7-1b7285aff15f",
"assignerShortName": "qualcomm",
"cveId": "CVE-2015-9166",
"datePublished": "2018-04-18T14:00:00.000Z",
"dateReserved": "2017-08-16T00:00:00.000Z",
"dateUpdated": "2024-09-16T18:44:40.898Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
FKIE_CVE-2015-9166
Vulnerability from fkie_nvd - Published: 2018-04-18 14:29 - Updated: 2024-11-21 02:39| URL | Tags | ||
|---|---|---|---|
| product-security@qualcomm.com | http://www.securityfocus.com/bid/103671 | Third Party Advisory, VDB Entry | |
| product-security@qualcomm.com | https://source.android.com/security/bulletin/2018-04-01 | Vendor Advisory | |
| af854a3a-2127-422b-91ae-364da2661108 | http://www.securityfocus.com/bid/103671 | Third Party Advisory, VDB Entry | |
| af854a3a-2127-422b-91ae-364da2661108 | https://source.android.com/security/bulletin/2018-04-01 | Vendor Advisory |
{
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A960B86A-C397-4ACB-AEE6-55F316D32949",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D79B8959-3D1E-4B48-9181-D75FE90AAF98",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A35FECFB-60AE-42A8-BCBB-FEA7D5826D49",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E9765187-8653-4D66-B230-B2CE862AC5C0",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "94CB547F-0078-47CD-B511-06DE96882D5A",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:ipq4019:-:*:*:*:*:*:*:*",
"matchCriteriaId": "AA679375-BB14-4B24-8AD9-B2BFBACE2FDB",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E08016A2-E4FE-4E9C-A915-C66BE157AFB5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_820a:-:*:*:*:*:*:*:*",
"matchCriteriaId": "018452D0-007C-4740-B2AF-E5C8BBAC310F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "35B7E25E-FA92-4C36-883C-CFF36F4B3507",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*",
"matchCriteriaId": "ECD99C6F-2444-4A5E-A517-0C8023DDF23D",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FE28A59C-7AA6-4B85-84E8-07852B96108E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5DEE828B-09A7-4AC1-8134-491A7C87C118",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0FA80D57-3191-47CF-AD3F-9F2D64E443FE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B2AFB212-F01A-4CEB-8DB4-2E0CC2308CB6",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E0986EF1-0974-488E-84C4-6880F876CE55",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8C08BA58-2EBC-4A22-85A4-2ECD54693B9B",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "27110478-4C08-49E6-BD53-8BAAD9D5BD65",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3664D302-D22A-4B25-B534-3097AE2F8573",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "AC3C20F8-9EFD-457C-B0B2-DA3C44A8B26D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4B562043-7A0C-4692-A94F-EF4086BAA654",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F683C42D-A310-4369-9689-3DBC9288591E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_410:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0EADE10A-0F63-4149-8F03-030673D6D7CE",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A78C9449-5EB0-459B-AA72-EFF00592C30A",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_412:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2D583172-F1F1-4DF8-99CE-B94A84D14CCD",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C56BC939-2FE8-4AB4-B638-35C83B224005",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_425:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E36C12E2-7064-41E6-B357-3F0E6E6D0A0F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_430_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BE5C66CC-B00C-4581-B8FB-0632232E480D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_430:-:*:*:*:*:*:*:*",
"matchCriteriaId": "87F57247-08CD-473E-A517-F9E85BFC7BEA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_450_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E07C621F-0BC0-40C1-9678-1AF6498AC487",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_450:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9C621A62-E346-406B-9D20-8FF6C2B0851F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_615_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "549E6F7E-A54F-423F-BD4A-A8FB97DBD39E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_615:-:*:*:*:*:*:*:*",
"matchCriteriaId": "992C3835-7183-4D96-8647-DD9916880323",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_616_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7B95CCC-37F1-4768-8D64-CA2028E93E03",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_616:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D1426161-4F7C-44B1-AA9E-EA661AA68947",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_415_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "ECF81213-DE2D-4C4B-99E8-71AFD87E92CD",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_415:-:*:*:*:*:*:*:*",
"matchCriteriaId": "95E826EF-343B-47FA-AB54-F13E868CE6A7",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_617_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D27A1760-8D1B-4172-B6CE-65C72332F103",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_617:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CC5F96F1-D3FB-482B-A3C8-57BA4DE86D5E",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_625_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "06E0CC35-AC20-42D7-8FEA-CA4685E33E72",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_625:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4A2C4DED-2367-4736-A0AF-C8356F1271AD",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BC1650DB-FDF8-4BE5-9437-8ADA11A07116",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_650:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B51DD51F-4BDE-497B-89E5-551D10CF3442",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0752054B-2C29-4490-ADC8-29F82BAA17E6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_652:-:*:*:*:*:*:*:*",
"matchCriteriaId": "005038B5-BCB7-4A23-8562-ACEF6E156C1F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_800_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "67E0DD11-0B28-4B6D-BDB7-0DBFA34A7187",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_800:-:*:*:*:*:*:*:*",
"matchCriteriaId": "551512D0-ED24-4B5A-BEB2-B090BB8DEE0C",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_808_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "33257838-2D70-4C43-8EE8-7538764EFFD9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_808:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1B2D83E1-F1F2-48E5-B3E0-806DAB14B60B",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "95B4B4D4-0357-4E1D-9B72-635106D632CF",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_810:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2F992088-5E31-4625-8C3B-CE7F946C61F2",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E077FC03-F86F-417A-A3E6-BC88CB85C6F0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_820:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E016356C-94ED-4CDD-8351-97D265FE036E",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1CFF35A3-1472-4665-9DAB-1ABC45C0D5B4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F930E9BF-C502-49C6-8BE8-9A711B89FA1B",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0A2D2B3B-CB28-46AA-9117-A7FA371FDE80",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*",
"matchCriteriaId": "DE18BF66-B0DB-48BB-B43A-56F01821F5A3",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0C10C7CB-3B66-4F17-8146-6A85611E2BA9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B9DA765F-53DE-4FB0-B825-6C11B3177641",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks."
},
{
"lang": "es",
"value": "En Android, antes del nivel de parche de seguridad del 2018-04-05 o antes en Qualcomm Snapdragon Automobile, Snapdragon Mobile y Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845 y SD 850, los mecanismos de provisi\u00f3n de DRM empleados en aplicaciones QSEE tienen una caracter\u00edstica para evitar a\u00fan m\u00e1s el aprovisionamiento. Esto se hace creando un archivo SFS llamado \u0027finalize_prov_flag.data\u0027 al finalizar el aprovisionamiento. Cuando esta caracter\u00edstica est\u00e1 activada, las llamadas de aprovisionamiento buscan la existencia del archivo para decidir si realizar aprovisionamiento o no. La implementaci\u00f3n actual permite el aprovisionamiento sin suficientes comprobaciones."
}
],
"id": "CVE-2015-9166",
"lastModified": "2024-11-21T02:39:56.830",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": true,
"baseSeverity": "MEDIUM",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0,
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.0"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2018-04-18T14:29:05.870",
"references": [
{
"source": "product-security@qualcomm.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securityfocus.com/bid/103671"
},
{
"source": "product-security@qualcomm.com",
"tags": [
"Vendor Advisory"
],
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securityfocus.com/bid/103671"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
],
"url": "https://source.android.com/security/bulletin/2018-04-01"
}
],
"sourceIdentifier": "product-security@qualcomm.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-19"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
GHSA-W364-QGRH-WR5R
Vulnerability from github – Published: 2022-05-14 03:24 – Updated: 2022-05-14 03:24In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called 'finalize_prov_flag.data' at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks.
{
"affected": [],
"aliases": [
"CVE-2015-9166"
],
"database_specific": {
"cwe_ids": [],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-04-18T14:29:00Z",
"severity": "HIGH"
},
"details": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks.",
"id": "GHSA-w364-qgrh-wr5r",
"modified": "2022-05-14T03:24:12Z",
"published": "2022-05-14T03:24:12Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-9166"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/103671"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
CERTFR-2018-AVI-164
Vulnerability from certfr_avis - Published: 2018-04-03 - Updated: 2018-04-03
De multiples vulnérabilités ont été découvertes dans Google Android. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
None| Title | Publication Time | Tags | ||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Google Android toutes versions n\u0027int\u00e9grant pas le correctif de s\u00e9curit\u00e9 du 02 avril 2018",
"product": {
"name": "Android",
"vendor": {
"name": "Google",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2017-13077",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13077"
},
{
"name": "CVE-2017-5754",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-5754"
},
{
"name": "CVE-2016-5348",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-5348"
},
{
"name": "CVE-2017-8269",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-8269"
},
{
"name": "CVE-2017-17449",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-17449"
},
{
"name": "CVE-2017-15115",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15115"
},
{
"name": "CVE-2017-17712",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-17712"
},
{
"name": "CVE-2017-17770",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-17770"
},
{
"name": "CVE-2017-15855",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15855"
},
{
"name": "CVE-2016-10472",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10472"
},
{
"name": "CVE-2016-10437",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10437"
},
{
"name": "CVE-2014-10055",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10055"
},
{
"name": "CVE-2017-14890",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14890"
},
{
"name": "CVE-2016-10392",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10392"
},
{
"name": "CVE-2014-10052",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10052"
},
{
"name": "CVE-2018-3563",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3563"
},
{
"name": "CVE-2016-10406",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10406"
},
{
"name": "CVE-2015-9190",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9190"
},
{
"name": "CVE-2015-9184",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9184"
},
{
"name": "CVE-2016-10492",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10492"
},
{
"name": "CVE-2015-9197",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9197"
},
{
"name": "CVE-2017-18074",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18074"
},
{
"name": "CVE-2017-18127",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18127"
},
{
"name": "CVE-2014-10054",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10054"
},
{
"name": "CVE-2014-9989",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9989"
},
{
"name": "CVE-2016-10435",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10435"
},
{
"name": "CVE-2017-13305",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13305"
},
{
"name": "CVE-2015-9217",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9217"
},
{
"name": "CVE-2016-10462",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10462"
},
{
"name": "CVE-2018-3599",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3599"
},
{
"name": "CVE-2016-10426",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10426"
},
{
"name": "CVE-2015-9135",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9135"
},
{
"name": "CVE-2017-13285",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13285"
},
{
"name": "CVE-2016-10385",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10385"
},
{
"name": "CVE-2014-10063",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10063"
},
{
"name": "CVE-2015-9185",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9185"
},
{
"name": "CVE-2016-10410",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10410"
},
{
"name": "CVE-2017-13297",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13297"
},
{
"name": "CVE-2017-14880",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14880"
},
{
"name": "CVE-2014-10053",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10053"
},
{
"name": "CVE-2015-9123",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9123"
},
{
"name": "CVE-2017-18147",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18147"
},
{
"name": "CVE-2015-9134",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9134"
},
{
"name": "CVE-2015-9137",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9137"
},
{
"name": "CVE-2017-18137",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18137"
},
{
"name": "CVE-2017-18146",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18146"
},
{
"name": "CVE-2016-10473",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10473"
},
{
"name": "CVE-2016-10497",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10497"
},
{
"name": "CVE-2016-10448",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10448"
},
{
"name": "CVE-2018-3592",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3592"
},
{
"name": "CVE-2015-9114",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9114"
},
{
"name": "CVE-2014-10059",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10059"
},
{
"name": "CVE-2015-9126",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9126"
},
{
"name": "CVE-2016-10460",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10460"
},
{
"name": "CVE-2017-13276",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13276"
},
{
"name": "CVE-2016-10466",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10466"
},
{
"name": "CVE-2014-9990",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9990"
},
{
"name": "CVE-2015-9172",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9172"
},
{
"name": "CVE-2016-10427",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10427"
},
{
"name": "CVE-2015-9152",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9152"
},
{
"name": "CVE-2016-10438",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10438"
},
{
"name": "CVE-2015-9066",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9066"
},
{
"name": "CVE-2015-9164",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9164"
},
{
"name": "CVE-2016-10491",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10491"
},
{
"name": "CVE-2015-9131",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9131"
},
{
"name": "CVE-2016-10461",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10461"
},
{
"name": "CVE-2015-9130",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9130"
},
{
"name": "CVE-2017-18133",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18133"
},
{
"name": "CVE-2016-10451",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10451"
},
{
"name": "CVE-2014-10045",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10045"
},
{
"name": "CVE-2016-10386",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10386"
},
{
"name": "CVE-2018-5825",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5825"
},
{
"name": "CVE-2017-15822",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15822"
},
{
"name": "CVE-2014-9998",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9998"
},
{
"name": "CVE-2014-9997",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9997"
},
{
"name": "CVE-2015-9063",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9063"
},
{
"name": "CVE-2015-8593",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-8593"
},
{
"name": "CVE-2018-5820",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5820"
},
{
"name": "CVE-2015-9218",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9218"
},
{
"name": "CVE-2015-9208",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9208"
},
{
"name": "CVE-2015-9196",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9196"
},
{
"name": "CVE-2015-9064",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9064"
},
{
"name": "CVE-2017-18071",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18071"
},
{
"name": "CVE-2015-9209",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9209"
},
{
"name": "CVE-2016-10489",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10489"
},
{
"name": "CVE-2015-9133",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9133"
},
{
"name": "CVE-2017-13277",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13277"
},
{
"name": "CVE-2016-10442",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10442"
},
{
"name": "CVE-2015-9144",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9144"
},
{
"name": "CVE-2016-10482",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10482"
},
{
"name": "CVE-2017-13296",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13296"
},
{
"name": "CVE-2015-9151",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9151"
},
{
"name": "CVE-2015-9138",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9138"
},
{
"name": "CVE-2017-18138",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18138"
},
{
"name": "CVE-2015-9166",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9166"
},
{
"name": "CVE-2015-9188",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9188"
},
{
"name": "CVE-2016-10407",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10407"
},
{
"name": "CVE-2017-18126",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18126"
},
{
"name": "CVE-2016-10490",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10490"
},
{
"name": "CVE-2018-5821",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5821"
},
{
"name": "CVE-2016-10487",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10487"
},
{
"name": "CVE-2015-9203",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9203"
},
{
"name": "CVE-2016-10484",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10484"
},
{
"name": "CVE-2015-9143",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9143"
},
{
"name": "CVE-2016-10501",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10501"
},
{
"name": "CVE-2016-10381",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10381"
},
{
"name": "CVE-2016-10454",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10454"
},
{
"name": "CVE-2014-9976",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9976"
},
{
"name": "CVE-2017-18139",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18139"
},
{
"name": "CVE-2015-0576",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-0576"
},
{
"name": "CVE-2017-13278",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13278"
},
{
"name": "CVE-2017-13291",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13291"
},
{
"name": "CVE-2016-10411",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10411"
},
{
"name": "CVE-2017-18136",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18136"
},
{
"name": "CVE-2018-3568",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3568"
},
{
"name": "CVE-2016-10493",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10493"
},
{
"name": "CVE-2017-13288",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13288"
},
{
"name": "CVE-2016-10430",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10430"
},
{
"name": "CVE-2014-9971",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9971"
},
{
"name": "CVE-2018-3591",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3591"
},
{
"name": "CVE-2017-18128",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18128"
},
{
"name": "CVE-2017-18132",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18132"
},
{
"name": "CVE-2017-18144",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18144"
},
{
"name": "CVE-2015-9127",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9127"
},
{
"name": "CVE-2018-5824",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5824"
},
{
"name": "CVE-2015-9163",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9163"
},
{
"name": "CVE-2016-10440",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10440"
},
{
"name": "CVE-2015-9157",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9157"
},
{
"name": "CVE-2015-9221",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9221"
},
{
"name": "CVE-2016-10481",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10481"
},
{
"name": "CVE-2016-10436",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10436"
},
{
"name": "CVE-2015-9201",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9201"
},
{
"name": "CVE-2015-9147",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9147"
},
{
"name": "CVE-2014-10050",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10050"
},
{
"name": "CVE-2018-3566",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3566"
},
{
"name": "CVE-2016-10486",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10486"
},
{
"name": "CVE-2018-5822",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5822"
},
{
"name": "CVE-2016-10458",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10458"
},
{
"name": "CVE-2016-10390",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10390"
},
{
"name": "CVE-2017-13307",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13307"
},
{
"name": "CVE-2016-10384",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10384"
},
{
"name": "CVE-2015-9112",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9112"
},
{
"name": "CVE-2015-9192",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9192"
},
{
"name": "CVE-2017-13301",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13301"
},
{
"name": "CVE-2016-10417",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10417"
},
{
"name": "CVE-2015-9210",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9210"
},
{
"name": "CVE-2015-9167",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9167"
},
{
"name": "CVE-2015-9108",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9108"
},
{
"name": "CVE-2015-9140",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9140"
},
{
"name": "CVE-2015-9113",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9113"
},
{
"name": "CVE-2016-10431",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10431"
},
{
"name": "CVE-2016-10443",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10443"
},
{
"name": "CVE-2017-18143",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18143"
},
{
"name": "CVE-2014-10051",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10051"
},
{
"name": "CVE-2015-9193",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9193"
},
{
"name": "CVE-2017-13303",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13303"
},
{
"name": "CVE-2016-10496",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10496"
},
{
"name": "CVE-2017-11075",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-11075"
},
{
"name": "CVE-2017-15853",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15853"
},
{
"name": "CVE-2014-9987",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9987"
},
{
"name": "CVE-2017-13300",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13300"
},
{
"name": "CVE-2016-10478",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10478"
},
{
"name": "CVE-2017-13292",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13292"
},
{
"name": "CVE-2017-18145",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18145"
},
{
"name": "CVE-2014-9993",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9993"
},
{
"name": "CVE-2016-10424",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10424"
},
{
"name": "CVE-2016-10441",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10441"
},
{
"name": "CVE-2016-10474",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10474"
},
{
"name": "CVE-2015-9161",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9161"
},
{
"name": "CVE-2015-9205",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9205"
},
{
"name": "CVE-2016-10469",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10469"
},
{
"name": "CVE-2015-9141",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9141"
},
{
"name": "CVE-2016-10439",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10439"
},
{
"name": "CVE-2015-9179",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9179"
},
{
"name": "CVE-2017-13279",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13279"
},
{
"name": "CVE-2016-10418",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10418"
},
{
"name": "CVE-2018-3593",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3593"
},
{
"name": "CVE-2017-13283",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13283"
},
{
"name": "CVE-2015-9194",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9194"
},
{
"name": "CVE-2016-10450",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10450"
},
{
"name": "CVE-2015-9128",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9128"
},
{
"name": "CVE-2015-9153",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9153"
},
{
"name": "CVE-2016-10480",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10480"
},
{
"name": "CVE-2016-10416",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10416"
},
{
"name": "CVE-2017-18135",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18135"
},
{
"name": "CVE-2017-13290",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13290"
},
{
"name": "CVE-2015-9219",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9219"
},
{
"name": "CVE-2015-9189",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9189"
},
{
"name": "CVE-2016-10477",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10477"
},
{
"name": "CVE-2016-10471",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10471"
},
{
"name": "CVE-2015-9220",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9220"
},
{
"name": "CVE-2015-9211",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9211"
},
{
"name": "CVE-2015-9129",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9129"
},
{
"name": "CVE-2015-9165",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9165"
},
{
"name": "CVE-2015-9174",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9174"
},
{
"name": "CVE-2014-10056",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10056"
},
{
"name": "CVE-2014-10057",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10057"
},
{
"name": "CVE-2015-9224",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9224"
},
{
"name": "CVE-2018-5828",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5828"
},
{
"name": "CVE-2015-9195",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9195"
},
{
"name": "CVE-2016-10499",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10499"
},
{
"name": "CVE-2015-9181",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9181"
},
{
"name": "CVE-2017-13281",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13281"
},
{
"name": "CVE-2015-9065",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9065"
},
{
"name": "CVE-2016-10415",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10415"
},
{
"name": "CVE-2015-9187",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9187"
},
{
"name": "CVE-2015-9178",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9178"
},
{
"name": "CVE-2015-9110",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9110"
},
{
"name": "CVE-2015-9119",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9119"
},
{
"name": "CVE-2017-14894",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14894"
},
{
"name": "CVE-2016-10459",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10459"
},
{
"name": "CVE-2016-10432",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10432"
},
{
"name": "CVE-2015-9120",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9120"
},
{
"name": "CVE-2017-13294",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13294"
},
{
"name": "CVE-2015-9177",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9177"
},
{
"name": "CVE-2015-9136",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9136"
},
{
"name": "CVE-2016-10444",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10444"
},
{
"name": "CVE-2015-9186",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9186"
},
{
"name": "CVE-2016-10428",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10428"
},
{
"name": "CVE-2017-13306",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13306"
},
{
"name": "CVE-2017-18072",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18072"
},
{
"name": "CVE-2015-9118",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9118"
},
{
"name": "CVE-2017-13304",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13304"
},
{
"name": "CVE-2015-9171",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9171"
},
{
"name": "CVE-2016-10447",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10447"
},
{
"name": "CVE-2018-3598",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3598"
},
{
"name": "CVE-2015-9206",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9206"
},
{
"name": "CVE-2015-9111",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9111"
},
{
"name": "CVE-2015-9213",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9213"
},
{
"name": "CVE-2016-10479",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10479"
},
{
"name": "CVE-2015-9122",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9122"
},
{
"name": "CVE-2018-5827",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5827"
},
{
"name": "CVE-2018-3594",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3594"
},
{
"name": "CVE-2015-9109",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9109"
},
{
"name": "CVE-2017-18140",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18140"
},
{
"name": "CVE-2016-10409",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10409"
},
{
"name": "CVE-2015-9222",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9222"
},
{
"name": "CVE-2015-9170",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9170"
},
{
"name": "CVE-2015-9176",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9176"
},
{
"name": "CVE-2017-13284",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13284"
},
{
"name": "CVE-2015-9215",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9215"
},
{
"name": "CVE-2017-13282",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13282"
},
{
"name": "CVE-2017-18073",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18073"
},
{
"name": "CVE-2014-9986",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9986"
},
{
"name": "CVE-2015-0574",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-0574"
},
{
"name": "CVE-2017-15836",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15836"
},
{
"name": "CVE-2015-9173",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9173"
},
{
"name": "CVE-2015-9159",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9159"
},
{
"name": "CVE-2018-3567",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3567"
},
{
"name": "CVE-2016-10446",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10446"
},
{
"name": "CVE-2018-3584",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3584"
},
{
"name": "CVE-2016-10452",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10452"
},
{
"name": "CVE-2017-18134",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18134"
},
{
"name": "CVE-2017-13286",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13286"
},
{
"name": "CVE-2014-10043",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10043"
},
{
"name": "CVE-2014-9996",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9996"
},
{
"name": "CVE-2016-10485",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10485"
},
{
"name": "CVE-2016-10467",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10467"
},
{
"name": "CVE-2017-18130",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18130"
},
{
"name": "CVE-2016-10425",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10425"
},
{
"name": "CVE-2015-9146",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9146"
},
{
"name": "CVE-2015-9158",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9158"
},
{
"name": "CVE-2018-3596",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3596"
},
{
"name": "CVE-2017-13275",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13275"
},
{
"name": "CVE-2016-10498",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10498"
},
{
"name": "CVE-2016-10483",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10483"
},
{
"name": "CVE-2017-15837",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-15837"
},
{
"name": "CVE-2015-9142",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9142"
},
{
"name": "CVE-2014-10047",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10047"
},
{
"name": "CVE-2014-9995",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9995"
},
{
"name": "CVE-2017-8274",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-8274"
},
{
"name": "CVE-2015-9198",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9198"
},
{
"name": "CVE-2014-9972",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9972"
},
{
"name": "CVE-2016-10421",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10421"
},
{
"name": "CVE-2018-5823",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5823"
},
{
"name": "CVE-2017-18125",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18125"
},
{
"name": "CVE-2017-11011",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-11011"
},
{
"name": "CVE-2016-10412",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10412"
},
{
"name": "CVE-2015-9169",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9169"
},
{
"name": "CVE-2016-10449",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10449"
},
{
"name": "CVE-2016-10434",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10434"
},
{
"name": "CVE-2015-9191",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9191"
},
{
"name": "CVE-2016-10380",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10380"
},
{
"name": "CVE-2014-10058",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10058"
},
{
"name": "CVE-2015-9124",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9124"
},
{
"name": "CVE-2015-9212",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9212"
},
{
"name": "CVE-2017-8275",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-8275"
},
{
"name": "CVE-2017-13287",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13287"
},
{
"name": "CVE-2016-10445",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10445"
},
{
"name": "CVE-2015-9175",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9175"
},
{
"name": "CVE-2018-5826",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-5826"
},
{
"name": "CVE-2015-9200",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9200"
},
{
"name": "CVE-2016-10464",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10464"
},
{
"name": "CVE-2015-8594",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-8594"
},
{
"name": "CVE-2014-10048",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10048"
},
{
"name": "CVE-2016-10495",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10495"
},
{
"name": "CVE-2015-9115",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9115"
},
{
"name": "CVE-2015-9199",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9199"
},
{
"name": "CVE-2015-9156",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9156"
},
{
"name": "CVE-2015-9183",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9183"
},
{
"name": "CVE-2017-13302",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13302"
},
{
"name": "CVE-2014-10044",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10044"
},
{
"name": "CVE-2015-9182",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9182"
},
{
"name": "CVE-2016-10414",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10414"
},
{
"name": "CVE-2014-9991",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9991"
},
{
"name": "CVE-2015-9162",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9162"
},
{
"name": "CVE-2016-10419",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10419"
},
{
"name": "CVE-2016-10429",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10429"
},
{
"name": "CVE-2015-9132",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9132"
},
{
"name": "CVE-2017-13295",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13295"
},
{
"name": "CVE-2014-10046",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10046"
},
{
"name": "CVE-2014-9994",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9994"
},
{
"name": "CVE-2015-9223",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9223"
},
{
"name": "CVE-2014-9985",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9985"
},
{
"name": "CVE-2017-18129",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18129"
},
{
"name": "CVE-2015-9160",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9160"
},
{
"name": "CVE-2014-9981",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9981"
},
{
"name": "CVE-2016-10475",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10475"
},
{
"name": "CVE-2017-13293",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13293"
},
{
"name": "CVE-2015-9204",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9204"
},
{
"name": "CVE-2017-13280",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13280"
},
{
"name": "CVE-2015-9149",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9149"
},
{
"name": "CVE-2016-10494",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10494"
},
{
"name": "CVE-2016-10457",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10457"
},
{
"name": "CVE-2015-9202",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9202"
},
{
"name": "CVE-2016-10387",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10387"
},
{
"name": "CVE-2016-10420",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10420"
},
{
"name": "CVE-2015-9139",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9139"
},
{
"name": "CVE-2016-10476",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10476"
},
{
"name": "CVE-2017-13274",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13274"
},
{
"name": "CVE-2016-10456",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10456"
},
{
"name": "CVE-2014-9988",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-9988"
},
{
"name": "CVE-2016-10422",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10422"
},
{
"name": "CVE-2015-9150",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9150"
},
{
"name": "CVE-2017-13298",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13298"
},
{
"name": "CVE-2017-18142",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-18142"
},
{
"name": "CVE-2014-10062",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10062"
},
{
"name": "CVE-2016-10423",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10423"
},
{
"name": "CVE-2015-9148",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9148"
},
{
"name": "CVE-2015-9180",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9180"
},
{
"name": "CVE-2014-10039",
"url": "https://www.cve.org/CVERecord?id=CVE-2014-10039"
},
{
"name": "CVE-2017-1653",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-1653"
},
{
"name": "CVE-2015-9145",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9145"
},
{
"name": "CVE-2017-13299",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13299"
},
{
"name": "CVE-2018-3590",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3590"
},
{
"name": "CVE-2015-9207",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9207"
},
{
"name": "CVE-2017-13267",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13267"
},
{
"name": "CVE-2015-9116",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9116"
},
{
"name": "CVE-2017-13289",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-13289"
},
{
"name": "CVE-2016-10455",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10455"
},
{
"name": "CVE-2018-3589",
"url": "https://www.cve.org/CVERecord?id=CVE-2018-3589"
},
{
"name": "CVE-2016-10433",
"url": "https://www.cve.org/CVERecord?id=CVE-2016-10433"
},
{
"name": "CVE-2015-9216",
"url": "https://www.cve.org/CVERecord?id=CVE-2015-9216"
}
],
"initial_release_date": "2018-04-03T00:00:00",
"last_revision_date": "2018-04-03T00:00:00",
"links": [],
"reference": "CERTFR-2018-AVI-164",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2018-04-03T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Google Android.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un\nprobl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur, une ex\u00e9cution de code\narbitraire \u00e0 distance et un d\u00e9ni de service \u00e0 distance.\n",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans Google Android",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Android du 02 avril 2018",
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Pixel/Nexus du 02 avril 2018",
"url": "https://source.android.com/security/bulletin/pixel/2018-04-01"
}
]
}
GSD-2015-9166
Vulnerability from gsd - Updated: 2023-12-13 01:20{
"GSD": {
"alias": "CVE-2015-9166",
"description": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks.",
"id": "GSD-2015-9166"
},
"gsd": {
"metadata": {
"exploitCode": "unknown",
"remediation": "unknown",
"reportConfidence": "confirmed",
"type": "vulnerability"
},
"osvSchema": {
"aliases": [
"CVE-2015-9166"
],
"details": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks.",
"id": "GSD-2015-9166",
"modified": "2023-12-13T01:20:02.385303Z",
"schema_version": "1.4.0"
}
},
"namespaces": {
"cve.org": {
"CVE_data_meta": {
"ASSIGNER": "product-security@qualcomm.com",
"DATE_PUBLIC": "2018-04-02T00:00:00",
"ID": "CVE-2015-9166",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear",
"version": {
"version_data": [
{
"version_value": "IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850"
}
]
}
}
]
},
"vendor_name": "Qualcomm, Inc."
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Access Control in Core."
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://source.android.com/security/bulletin/2018-04-01",
"refsource": "CONFIRM",
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"name": "103671",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/103671"
}
]
}
},
"nvd.nist.gov": {
"configurations": {
"CVE_data_version": "4.0",
"nodes": [
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:ipq4019:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_820a_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_820a:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:mdm9650:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_410:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_412:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_425_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_425:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_430_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_430:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_450_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_450:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_615_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_615:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_616_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_616:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_415_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_415:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_617_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_617:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_625_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_625:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_650:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_652:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_800_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_800:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_808_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_808:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_810:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_820_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_820:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_835_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_835:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_845_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_845:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
},
{
"children": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:qualcomm:sd_850_firmware:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:h:qualcomm:sd_850:-:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": false
}
],
"operator": "OR"
}
],
"cpe_match": [],
"operator": "AND"
}
]
},
"cve": {
"CVE_data_meta": {
"ASSIGNER": "security.cna@qualcomm.com",
"ID": "CVE-2015-9166"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "en",
"value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, DRM provisioning mechanisms used in QSEE applications have a feature to prevent further provisioning. This is done by creating an SFS file called \u0027finalize_prov_flag.data\u0027 at the end of provisioning. When this feature is enabled, provisioning calls check for the existence of the file in order to decide whether to do provisioning or not. Current implementation allows provisioning without sufficient checks."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "en",
"value": "CWE-19"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://source.android.com/security/bulletin/2018-04-01",
"refsource": "CONFIRM",
"tags": [
"Vendor Advisory"
],
"url": "https://source.android.com/security/bulletin/2018-04-01"
},
{
"name": "103671",
"refsource": "BID",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securityfocus.com/bid/103671"
}
]
}
},
"impact": {
"baseMetricV2": {
"acInsufInfo": true,
"cvssV2": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0,
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"severity": "MEDIUM",
"userInteractionRequired": false
},
"baseMetricV3": {
"cvssV3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.0"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
},
"lastModifiedDate": "2018-05-11T14:04Z",
"publishedDate": "2018-04-18T14:29Z"
}
}
}
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.