Vulnerabilities > CVE-2015-9221 - NULL Pointer Dereference vulnerability in Qualcomm SD 400 Firmware, SD 800 Firmware and SD 810 Firmware

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
qualcomm
CWE-476
critical

Summary

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers passed by secure apps could lead to an untrusted pointer dereference.

Common Weakness Enumeration (CWE)