CVE-2014-9974 is a critical vulnerability affecting Qualcomm products running Android with Linux kernel releases from CAF, stemming from missing buffer length validation in the Keymaster component. With a CVSS score of 9.8, it presents a severe risk, allowing unauthenticated attackers over the network to achieve high confidentiality, integrity, and availability impacts. Despite its critical severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The vulnerability remains unpatched in the KEV catalog and is inactive on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.