CVE-2014-9410 is a critical vulnerability affecting the Linux kernel 3.x, specifically within the MSM-VFE31 driver used in Qualcomm Innovation Center (QuIC) Android contributions and other products. It stems from a lack of validation for an 'id' value in the vfe31_proc_general function, allowing attackers to exploit this via crafted ioctl calls. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a severe risk, enabling remote attackers to gain privileges or cause a denial of service through memory corruption. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.