| Vulnerability Name: | CVE-2014-4322 (CCN-99884) | ||||||||||||||||||||
| Assigned: | 2014-12-22 | ||||||||||||||||||||
| Published: | 2014-12-22 | ||||||||||||||||||||
| Updated: | 2020-08-14 | ||||||||||||||||||||
| Summary: | drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application. | ||||||||||||||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-787 | ||||||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-4322 Source: XF Type: UNKNOWN qseecomdriver-cve20144322-dos(99884) Source: CCN Type: Packet Storm Security [01-27-2015] Android CVE-2014-7911 / CVE-2014-4322 Local Exploit Source: CCN Type: QCIR-2014-00008-1 Memory corruption in QSEECOM driver (CVE-2014-4322) Source: CONFIRM Type: Patch, Vendor Advisory https://www.codeaurora.org/projects/security-advisories/memory-corruption-qseecom-driver-cve-2014-4322 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [01-06-2015] Source: CCN Type: Qualcomm Web site Home Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-4322 | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||