CVE-2014-9798 is a denial-of-service vulnerability affecting the Qualcomm bootloader in Android on Nexus 5 devices, specifically in the platform/msm_shared/dev_tree.c component. This flaw allows a crafted application to cause an operating system outage due to improper validation of tag and aboot addresses. Rated Medium (CVSS 5.5), it requires local access and user interaction (UI:R) to achieve a high impact on availability. There is no public exploit code available, nor is it listed in CISA's KEV catalog, indicating a low likelihood of active exploitation despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.