{"api_version":"1","generated_at":"2026-05-07T01:39:14+00:00","cve":"CVE-2018-12014","urls":{"html":"https://cve.report/CVE-2018-12014","api":"https://cve.report/api/cve/CVE-2018-12014.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-12014","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-12014"},"summary":{"title":"CVE-2018-12014","description":"In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT module of freed pointer.","state":"PUBLIC","assigner":"product-security@qualcomm.com","published_at":"2019-02-11 15:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-476","CWE-416"],"metrics":[],"references":[{"url":"https://www.codeaurora.org/security-bulletin/2019/01/07/january-2019-code-aurora-security-bulletin","name":"https://www.codeaurora.org/security-bulletin/2019/01/07/january-2019-code-aurora-security-bulletin","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"January 2019 Code Aurora Security Bulletin - Code Aurora","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/106496","name":"106496","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-12014","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12014","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"12014","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12014","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@qualcomm.com","ID":"CVE-2018-12014","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android for MSM, Firefox OS for MSM, QRD Android","version":{"version_data":[{"version_value":"All Android releases from CAF using the Linux kernel"}]}}]},"vendor_name":"Qualcomm, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT module of freed pointer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Use After Free in HLOS Data"}]}]},"references":{"reference_data":[{"name":"https://www.codeaurora.org/security-bulletin/2019/01/07/january-2019-code-aurora-security-bulletin","refsource":"CONFIRM","url":"https://www.codeaurora.org/security-bulletin/2019/01/07/january-2019-code-aurora-security-bulletin"},{"name":"106496","refsource":"BID","url":"http://www.securityfocus.com/bid/106496"}]}},"nvd":{"publishedDate":"2019-02-11 15:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-476","CWE-416"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"12014","Ordinal":"128526","Title":"CVE-2018-12014","CVE":"CVE-2018-12014","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"12014","Ordinal":"1","NoteData":"In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT module of freed pointer.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"12014","Ordinal":"2","NoteData":"2019-02-11","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"12014","Ordinal":"3","NoteData":"2019-02-12","Type":"Other","Title":"Modified"}]}}}