{"api_version":"1","generated_at":"2026-07-23T07:36:48+00:00","cve":"CVE-2016-10389","urls":{"html":"https://cve.report/CVE-2016-10389","api":"https://cve.report/api/cve/CVE-2016-10389.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-10389","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-10389"},"summary":{"title":"CVE-2016-10389","description":"In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2017-08-18 18:29:00","updated_at":"2017-08-23 13:57:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/99465","name":"99465","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Qualcomm Components Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://source.android.com/security/bulletin/2017-07-01","name":"https://source.android.com/security/bulletin/2017-07-01","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Android Security Bulletin—July 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-10389","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10389","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"10389","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"10389","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2017-07-01T00:00:00","ID":"CVE-2016-10389","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"All Qualcomm products","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Input Validation in LK"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/2017-07-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2017-07-01"},{"name":"99465","refsource":"BID","url":"http://www.securityfocus.com/bid/99465"}]}},"nvd":{"publishedDate":"2017-08-18 18:29:00","lastModifiedDate":"2017-08-23 13:57:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"10389","Ordinal":"106310","Title":"CVE-2016-10389","CVE":"CVE-2016-10389","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"10389","Ordinal":"1","NoteData":"In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"10389","Ordinal":"2","NoteData":"2017-08-18","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"10389","Ordinal":"3","NoteData":"2017-08-19","Type":"Other","Title":"Modified"}]}}}