CVE-2015-9220
Last modified
CVE-2015-9220 is a vulnerability of currently unknown severity. In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, and SDX20, integer overflow occurs when the size of the firmware section is incorrectly encoded in the firmware image.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, and SDX20, integer overflow occurs when the size of the firmware section is incorrectly encoded in the firmware image.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9206 Firmware | All versions |
| Qualcomm | Mdm9607 Firmware | All versions |
| Qualcomm | Ipq4019 Firmware | All versions |
| Qualcomm | Ipq8064 Firmware | All versions |
| Qualcomm | Qca4531 Firmware | All versions |
| Qualcomm | Mdm9640 Firmware | All versions |
| Qualcomm | Qca6174a Firmware | All versions |
| Qualcomm | Mdm9650 Firmware | All versions |
| Qualcomm | Qca6574au Firmware | All versions |
| Qualcomm | Qca6584 Firmware | All versions |
| Qualcomm | Sd 210 Firmware | All versions |
| Qualcomm | Sd 212 Firmware | All versions |
| Qualcomm | Sd 205 Firmware | All versions |
| Qualcomm | Qca6584au Firmware | All versions |
| Qualcomm | Qca9377 Firmware | All versions |
| Qualcomm | Qca9378 Firmware | All versions |
| Qualcomm | Sd 425 Firmware | All versions |
| Qualcomm | Qca9379 Firmware | All versions |
| Qualcomm | Qca9558 Firmware | All versions |
| Qualcomm | Qca9880 Firmware | All versions |
| Qualcomm | Qca9886 Firmware | All versions |
| Qualcomm | Qca9980 Firmware | All versions |
| Qualcomm | Sd 625 Firmware | All versions |
| Qualcomm | Sd 810 Firmware | All versions |
| Qualcomm | Sd 820 Firmware | All versions |
| Qualcomm | Sdx20 Firmware | All versions |
References
- http://www.securityfocus.com/bid/103671Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
- http://www.securityfocus.com/bid/103671Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-04-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9220?
How severe is CVE-2015-9220?
How do I fix CVE-2015-9220?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-9214Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-9215In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9216In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9217In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9218In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9219In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9221In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9222In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9223In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9224In Android before 2018-04-05 or earlier security patch level…
- CVE-2015-9225Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-9226Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 a…
Are you affected by CVE-2015-9220?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
