ZeroHour

CVE-2016-10486

CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 450, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, and SD 820A, PD failure reason string from user PD is used directly in root PD, so if the buffer parameter is non-NULL terminated in Diag F3 APIs, a buffer overread occurs.

Vendors
qualcomm
Products
mdm9640 firmware, mdm9645 firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 450 firmware, sd 617 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 808 firmware, sd 810 firmware
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.