Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2014-9879

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Android on Nexus 5和7是美国谷歌(Google)公司和开放手持设备联盟(简称OHA)共同开发的一套运行于Nexus 5和7(智能手机)中并以Linux为基础的开源操作系统。Qualcomm是使用在其中的一个美国高通(Qualcomm)公司的设备专用的高通组件。 Nexus 5设备中的Android 2016-08-05之前版本中使用的Qualcomm组件中的mdss mdp3驱动程序存在安全漏洞,该漏洞源于程序没有正确验证user-space data数据。攻击者可借助特制的应用程序利用

AI Predicted 7.2 Difficulty: Moderate EPSS 0.45% · P38
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2014-9879

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The mdss mdp3 driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate user-space data, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769221 and Qualcomm internal bug CR524490.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Android on Nexus Qualcomm组件安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Android on Nexus 5和7是美国谷歌(Google)公司和开放手持设备联盟(简称OHA)共同开发的一套运行于Nexus 5和7(智能手机)中并以Linux为基础的开源操作系统。Qualcomm是使用在其中的一个美国高通(Qualcomm)公司的设备专用的高通组件。 Nexus 5设备中的Android 2016-08-05之前版本中使用的Qualcomm组件中的mdss mdp3驱动程序存在安全漏洞,该漏洞源于程序没有正确验证user-space data数据。攻击者可借助特制的应用程序利用
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2014-9879

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-9879

登录查看更多情报信息。

Vendor Advisories for CVE-2014-9879 (2)

Other References for CVE-2014-9879 (1)

Same Patch Batch · n/a · 2016-08-06 · 73 CVEs total

CVE-2014-9886 Android on Nexus Qualcomm组件安全漏洞
CVE-2015-8943 Android on Nexus Qualcomm组件安全漏洞
CVE-2015-8941 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9893 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9892 Android on Nexus 安全漏洞
CVE-2014-9891 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9890 Android on Nexus Qualcomm组件大小差一错误漏洞
CVE-2014-9889 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9888 Android on Nexus 安全漏洞
CVE-2014-9887 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9894 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9885 Android on Nexus Qualcomm组件格式化字符串漏洞
CVE-2014-9884 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9883 Android on Nexus Qualcomm组件整数溢出漏洞
CVE-2014-9882 Android on Nexus Qualcomm组件缓冲区溢出漏洞
CVE-2014-9881 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9880 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9878 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9877 Android on Nexus Qualcomm组件安全漏洞
CVE-2014-9876 Android on Nexus Qualcomm组件安全漏洞

Showing top 20 of 73 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-9879

No comments yet


Leave a comment