CVE-2016-10502
While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identity in Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835 and SDA660.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identity in Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835 and SDA660.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- qualcomm/mdm9206 firmware · qualcomm/mdm9607 firmware · qualcomm/mdm9650 firmware · qualcomm/sd 210 firmware · qualcomm/sd 212 firmware · qualcomm/sd 205 firmware · qualcomm/sd 835 firmware · qualcomm/sda660 firmware
- Source
- product-security@qualcomm.com
References
- http://www.securityfocus.com/bid/105838Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-11-01#qualcomm-componentsThird Party Advisory
- http://www.securityfocus.com/bid/105838Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-11-01#qualcomm-componentsThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.