← Vulnerability feed

Vulnerability record · CVE-2015-9132 · published 18 April 2018

CVE-2015-9132: Qualcomm fsm9055 firmware null pointer dereference vulnerability

Qualcomm · Fsm9055 Firmware

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Small Cell SoC FSM9055, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, and SD 810, possible arbitrary memory read due to untrusted pointer dereference when handling HLOS controlled values passed to the QSEE syscall helper.

7.5 CVSS 3.0 High EPSS 0.88% · top 42.1% CWE-476 · NULL pointer dereference
7.5CVSS 3.0 base score, v2 5.0
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Small Cell SoC FSM9055, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, and SD 810, possible arbitrary memory read due to untrusted pointer dereference when handling HLOS controlled values passed to the QSEE syscall helper.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-9132 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11076Qualcomm msm8909w firmware memory buffer overflow vulnerabilityOn some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can…EPSS 0.35%9.8CVE-2019-2325Qualcomm mdm9150 firmware vulnerabilityOut of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compu…EPSS 0.91%9.8CVE-2019-2332Qualcomm mdm9150 firmware out-of-bounds write vulnerabilityMemory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum…EPSS 0.91%9.8CVE-2019-2323Qualcomm mdm9150 firmware vulnerabilityLack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, Snapdragon C…EPSS 0.91%9.8CVE-2019-2258Qualcomm mdm9150 firmware out-of-bounds write vulnerabilityImproper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…EPSS 0.91%9.8CVE-2019-2283Qualcomm mdm9150 firmware out-of-bounds read vulnerabilityImproper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdr…EPSS 0.91%9.8CVE-2019-2324Qualcomm mdm9150 firmware memory buffer overflow vulnerabilityWhen ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapd…EPSS 0.91%9.8CVE-2019-2331Qualcomm mdm9150 firmware integer overflow vulnerabilityPossible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Com…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2015-9132), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.