{"api_version":"1","generated_at":"2026-07-23T04:30:32+00:00","cve":"CVE-2017-14869","urls":{"html":"https://cve.report/CVE-2017-14869","api":"https://cve.report/api/cve/CVE-2017-14869.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14869","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14869"},"summary":{"title":"CVE-2017-14869","description":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA partition, uninitialized data can be pushed to storage.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2018-01-10 22:29:00","updated_at":"2018-01-26 12:43:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://source.android.com/security/bulletin/pixel/2018-01-01","name":"https://source.android.com/security/bulletin/pixel/2018-01-01","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Pixel&hairsp;/&hairsp;Nexus Security Bulletin—January 2018  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14869","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14869","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14869","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"14869","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2018-01-02T00:00:00","ID":"CVE-2017-14869","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA partition, uninitialized data can be pushed to storage."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Exposure in Boot"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/pixel/2018-01-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/pixel/2018-01-01"}]}},"nvd":{"publishedDate":"2018-01-10 22:29:00","lastModifiedDate":"2018-01-26 12:43:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14869","Ordinal":"112340","Title":"CVE-2017-14869","CVE":"CVE-2017-14869","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14869","Ordinal":"1","NoteData":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA partition, uninitialized data can be pushed to storage.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14869","Ordinal":"2","NoteData":"2018-01-10","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14869","Ordinal":"3","NoteData":"2018-01-10","Type":"Other","Title":"Modified"}]}}}