CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2014-9972

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.

    Published: 18 Aug 2017
    7
    High

    CVE-2015-0576

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in HSDPA.

    Published: 18 Aug 2017
    6.1
    Medium

    CVE-2015-5057

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2015-5081

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified vectors.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-8594

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in RFA-1x.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9035

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a memory buffer fails to be freed after it is no longer needed potentially resulting in memory exhaustion.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9043

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer can be dereferenced upon the expiry of a timer.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9044

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9046

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9052

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached while processing a downlink message.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9068

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a mink syscall is not properly validated.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10344

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in LTE.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10347

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10380

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10385

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in IMS RCS.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8268

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer processing with invalid values leading to the driver performing a heap buffer over-read.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9411

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9968

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9969

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9973

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missing in a PlayReady DRM routine.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9974

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing in Keymaster.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9975

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9976

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9979

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a variable is uninitialized in a TrustZone system call potentially leading to the compromise of secure memory.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2014-9980

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a Sample App failed to check a length potentially leading to unauthorized access to secure memory.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-0574

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.

    Published: 18 Aug 2017
    5.3
    Medium

    CVE-2015-4071

    Last Modified: 20 Apr 2025

    The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-8592

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potentially resulting in Guest-OS memory corruption.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-8595

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in digital television/digital radio DRM.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-8596

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths is missing in malware protection.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9036

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a memory buffer resulting in adjacent memory getting corrupted.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9037

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlink 3G NAS message.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9038

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer may be dereferenced in the front end.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9039

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by a sequence of downlink messages.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9040

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9041

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when performing WCDMA radio tuning.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9045

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GERAN where a buffer can be overflown while taking power measurements.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9048

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packets.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9049

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responses from the USIM.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9050

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur during a CA call.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9053

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the processing of certain responses from the USIM.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9054

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer can be dereferenced during GAL decoding.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9055

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a memory management routine.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9060

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9061

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unauthorized access to secure memory.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9062

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an ELF file.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9063

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a procedure involving a remote UIM client.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9064

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9065

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9066

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an Inter-RAT procedure.

    Published: 18 Aug 2017