CVE-2016-10489

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, lack of address argument validation in qsee_get_tz_app_name() may lead to an untrusted pointer dereference.
References
Link Resource
http://www.securityfocus.com/bid/103671 Third Party Advisory VDB Entry
https://source.android.com/security/bulletin/2018-04-01 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-18 14:29

Updated : 2023-12-10 12:30


NVD link : CVE-2016-10489

Mitre link : CVE-2016-10489

CVE.ORG link : CVE-2016-10489


JSON object : View

Products Affected

qualcomm

  • sd_400_firmware
  • sd_400
CWE
CWE-476

NULL Pointer Dereference