Vulnerabilities > Qualcomm > SD 845 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-28 CVE-2017-18316 Unspecified vulnerability in Qualcomm products
Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm
7.2
2018-10-29 CVE-2018-11884 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11882 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11880 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11879 Integer Overflow or Wraparound vulnerability in Qualcomm SD 845 Firmware
When the buffer length passed is very large, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 845
local
low complexity
qualcomm CWE-190
7.2
2018-10-29 CVE-2018-11877 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11876 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11875 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm SD 845 Firmware and SD 850 Firmware
Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11874 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.2
2018-10-29 CVE-2018-11872 Improper Input Validation vulnerability in Qualcomm SD 845 Firmware, SD 850 Firmware and Sda660 Firmware
Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-20
7.2