AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-0974

LOW · CVSS 1.9 EPSS 0.33%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-08-25 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 1.9. It affects Linux, Android.

CVE
CVE-2014-0974
Severity
LOW
CVSS
1.9
EPSS
0.33%
Linux Android

Original NVD Description

The boot_linux_from_mmc function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate a certain address value, which allows attackers to write data to a controllable memory location by leveraging the ability to initiate an attempted boot of an arbitrary image.