In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, SD 400, and SD 800, calling qsee_app_entry_return() without first calling qsee_app_entry() will cause the stack to be restored to an older state resulting in a return to an unexpected location.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HQualcomm Mdm9625
HWQualcommall versionsQualcomm Mdm9625 Firmware
OSQualcommall versionsQualcomm Sd 400
HWQualcommall versionsQualcomm Sd 400 Firmware
OSQualcommall versionsQualcomm Sd 800
HWQualcommall versionsQualcomm Sd 800 Firmware
OSQualcommall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-1916CRITICAL9.8PL ✓same product
Buffer underflow w układach Qualcomm Snapdragon — brak walidacji ujemnych indeksów
CVE-2021-1919CRITICAL9.8PL ✓same product
Integer underflow w obsłudze RTCP na chipsetach Qualcomm Snapdragon
CVE-2021-1920CRITICAL9.8PL ✓same product
Integer underflow w obsłudze pakietów RTCP w układach Qualcomm Snapdragon
CVE-2020-11166CRITICAL9.1PL ✓same product
Qualcomm Snapdragon: out-of-bounds read w dekompresji nagłówków ROHC
CVE-2020-11170CRITICAL9.8PL ✓same product
Qualcomm Snapdragon — out-of-bounds memory access w obsłudze plików Vorbis