peter bassill · operator
$ cve CVE-2014-4322 JSON

CVE-2014-4322 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 2% (pctl 81)

Patch early

A public exploit exists.

Description

drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS2.04% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2014-12-24
Last modified2026-06-17

Affected (1)

VendorProduct
linuxlinux kernel

Public exploits

SourceTitleDate
exploit-dbNexus 5 Android 5.0 - Local Privilege Escalation2015-01-06

References

→ the Explorer  ·  watch your stack  ·  NVD