UBUNTU-CVE-2014-9894

Source
https://ubuntu.com/security/CVE-2014-9894
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-9894.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-9894
Related
  • CVE-2014-9894
Withdrawn
2025-06-23T15:52:40Z
Published
2016-08-06T10:59:00Z
Modified
2026-02-04T04:07:38.248578Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings end in a '\0' character, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28749708 and Qualcomm internal bug CR545736.

References

Affected packages

Ubuntu:Pro:16.04:LTS / linux-flo

Package

Name
linux-flo
Purl
pkg:deb/ubuntu/linux-flo@3.4.0-5.23?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.0-5.19
3.4.0-5.22
3.4.0-5.23

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-9894.json"

Ubuntu:Pro:16.04:LTS / linux-goldfish

Package

Name
linux-goldfish
Purl
pkg:deb/ubuntu/linux-goldfish@3.4.0-4.27?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.0-4.24
3.4.0-4.26
3.4.0-4.27

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-9894.json"

Ubuntu:Pro:16.04:LTS / linux-mako

Package

Name
linux-mako
Purl
pkg:deb/ubuntu/linux-mako@3.4.0-7.44?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.0-7.39
3.4.0-7.40
3.4.0-7.41
3.4.0-7.44

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-9894.json"