CVE-2014-9800: Integer Overflow
Published Jul 11, 2016
·Updated
Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28822150 and Qualcomm internal bug CR692478.
Affected Software
1 affected component
Google Android<=6.0.1
Event History
Jul 11, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
Which devices are identified as affected?
The issue affects Nexus 5 and Nexus 7 (2013) devices running Android versions before 2016-07-05.
2
What does an attacker need to exploit this vulnerability?
An attacker needs to get a crafted application executed on the affected device. The CVSS vector indicates local access, no required privileges, low attack complexity, and user interaction.
3
What is the likely impact of successful exploitation?
Successful exploitation can allow an attacker to gain privileges, with high potential impact to confidentiality, integrity, and availability.