CVE-2014-9985: Critical severity qualcomm mdm9635m firmware vulnerability
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, SD 400, and SD 800, TOCTOU condition may result in bypassing error condition checks, leading to undefined behavior.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-9985?
CVE-2014-9985 is a vulnerability found in Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, SD 400, and SD 800, which allows for bypassing error condition checks and may result in undefined behavior.
Who is affected by CVE-2014-9985?
Android devices using Qualcomm Snapdragon Mobile MDM9635M, SD 400, and SD 800 before 2018-04-05 or earlier security patch level are affected by CVE-2014-9985.
What is the severity of CVE-2014-9985?
CVE-2014-9985 has a severity rating of critical with a CVSS score of 9.8.
How can CVE-2014-9985 be exploited?
CVE-2014-9985 can be exploited by attackers who can trigger a TOCTOU (Time-of-Check to Time-of-Use) condition, leading to bypassing error condition checks and potentially causing undefined behavior.
Is there a patch available for CVE-2014-9985?
Yes, a security patch was released by Google for Android on 2018-04-05 to address CVE-2014-9985.