{"api_version":"1","generated_at":"2026-07-23T09:51:42+00:00","cve":"CVE-2017-14908","urls":{"html":"https://cve.report/CVE-2017-14908","api":"https://cve.report/api/cve/CVE-2017-14908.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14908","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14908"},"summary":{"title":"CVE-2017-14908","description":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify.","state":"PUBLISHED","assigner":"qualcomm","published_at":"2017-12-05 19:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-20","Improper Input Validation in SafeSwitch"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://source.android.com/security/bulletin/2017-12-01","name":"https://source.android.com/security/bulletin/2017-12-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Android Security Bulletin—December 2017  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102072","name":"http://www.securityfocus.com/bid/102072","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14908","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14908","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Qualcomm, Inc.","product":"Android for MSM, Firefox OS for MSM, QRD Android","version":"affected All Android releases from CAF using the Linux kernel","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14908","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"14908","cve":"CVE-2017-14908","epss":"0.001060000","percentile":"0.282840000","score_date":"2026-05-15","updated_at":"2026-05-16 00:02:07"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:42:22.286Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/2017-12-01"},{"name":"102072","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/102072"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Android for MSM, Firefox OS for MSM, QRD Android","vendor":"Qualcomm, Inc.","versions":[{"status":"affected","version":"All Android releases from CAF using the Linux kernel"}]}],"datePublic":"2017-12-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify."}],"problemTypes":[{"descriptions":[{"description":"Improper Input Validation in SafeSwitch","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-07T10:57:01.000Z","orgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","shortName":"qualcomm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/2017-12-01"},{"name":"102072","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/102072"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","DATE_PUBLIC":"2017-12-04T00:00:00","ID":"CVE-2017-14908","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Input Validation in SafeSwitch"}]}]},"references":{"reference_data":[{"name":"https://source.android.com/security/bulletin/2017-12-01","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2017-12-01"},{"name":"102072","refsource":"BID","url":"http://www.securityfocus.com/bid/102072"}]}}}},"cveMetadata":{"assignerOrgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","assignerShortName":"qualcomm","cveId":"CVE-2017-14908","datePublished":"2017-12-05T19:00:00.000Z","dateReserved":"2017-09-28T00:00:00.000Z","dateUpdated":"2024-09-16T17:28:24.998Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-05 19:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-20","Improper Input Validation in SafeSwitch"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14908","Ordinal":"1","Title":"CVE-2017-14908","CVE":"CVE-2017-14908","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14908","Ordinal":"1","NoteData":"In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify.","Type":"Description","Title":"CVE-2017-14908"},{"CveYear":"2017","CveId":"14908","Ordinal":"2","NoteData":"2017-12-05","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14908","Ordinal":"3","NoteData":"2017-12-07","Type":"Other","Title":"Modified"}]}}}