CVE-2015-9194
Summary
| CVE | CVE-2015-9194 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-18 14:29:00 UTC |
| Updated | 2018-05-09 15:05:00 UTC |
| Description | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 845, and Snapdragon_High_Med_2016, during module load at TZ Startup, memory statically allocated by modules was not being properly set to zero first. Allowing the module to execute without reset gives it access to information from previous app thus leading to information exposure. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Sd 205 | - | All | All | All |
| Hardware | Qualcomm | Sd 205 | - | All | All | All |
| Operating System | Qualcomm | Sd 205 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 205 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 210 | - | All | All | All |
| Hardware | Qualcomm | Sd 210 | - | All | All | All |
| Operating System | Qualcomm | Sd 210 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 210 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 212 | - | All | All | All |
| Hardware | Qualcomm | Sd 212 | - | All | All | All |
| Operating System | Qualcomm | Sd 212 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 212 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 400 | - | All | All | All |
| Hardware | Qualcomm | Sd 400 | - | All | All | All |
| Operating System | Qualcomm | Sd 400 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 400 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 425 | - | All | All | All |
| Hardware | Qualcomm | Sd 425 | - | All | All | All |
| Operating System | Qualcomm | Sd 425 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 425 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 427 | - | All | All | All |
| Hardware | Qualcomm | Sd 427 | - | All | All | All |
| Operating System | Qualcomm | Sd 427 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 427 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 430 | - | All | All | All |
| Hardware | Qualcomm | Sd 430 | - | All | All | All |
| Operating System | Qualcomm | Sd 430 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 430 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 435 | - | All | All | All |
| Hardware | Qualcomm | Sd 435 | - | All | All | All |
| Operating System | Qualcomm | Sd 435 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 435 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 450 | - | All | All | All |
| Hardware | Qualcomm | Sd 450 | - | All | All | All |
| Operating System | Qualcomm | Sd 450 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 450 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 617 | - | All | All | All |
| Hardware | Qualcomm | Sd 617 | - | All | All | All |
| Operating System | Qualcomm | Sd 617 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 617 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 625 | - | All | All | All |
| Hardware | Qualcomm | Sd 625 | - | All | All | All |
| Operating System | Qualcomm | Sd 625 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 625 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 650 | - | All | All | All |
| Hardware | Qualcomm | Sd 650 | - | All | All | All |
| Operating System | Qualcomm | Sd 650 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 650 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 652 | - | All | All | All |
| Hardware | Qualcomm | Sd 652 | - | All | All | All |
| Operating System | Qualcomm | Sd 652 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 652 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 800 | - | All | All | All |
| Hardware | Qualcomm | Sd 800 | - | All | All | All |
| Operating System | Qualcomm | Sd 800 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 800 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 845 | - | All | All | All |
| Hardware | Qualcomm | Sd 845 | - | All | All | All |
| Operating System | Qualcomm | Sd 845 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 845 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Android Security Bulletin—April 2018 | Android Open Source Project | CONFIRM | source.android.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.