Vulnerabilities > Qualcomm > SD 850 Firmware

DATE CVE VULNERABILITY TITLE RISK
2018-10-26 CVE-2018-11950 Improper Input Validation vulnerability in Qualcomm SD 845 Firmware and SD 850 Firmware
Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850
local
low complexity
qualcomm CWE-20
7.8
2018-10-26 CVE-2018-11854 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-119
7.8
2018-10-26 CVE-2018-11853 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016
local
low complexity
qualcomm CWE-119
7.8
2018-10-26 CVE-2018-11850 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of check on remaining length parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 625, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20
local
low complexity
qualcomm CWE-119
7.8
2018-10-26 CVE-2018-11849 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9886, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016
local
low complexity
qualcomm CWE-119
7.8
2018-10-26 CVE-2018-11846 Information Exposure vulnerability in Qualcomm products
The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850
local
high complexity
qualcomm CWE-200
4.7
2018-10-26 CVE-2018-11824 Out-of-bounds Write vulnerability in Qualcomm products
A stack-based buffer overflow can occur in a firmware routine in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-787
7.8
2018-10-26 CVE-2018-11822 Integer Overflow or Wraparound vulnerability in Qualcomm products
A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-190
7.8
2018-10-26 CVE-2018-11821 Integer Overflow or Wraparound vulnerability in Qualcomm products
Possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016
local
low complexity
qualcomm CWE-190
7.8
2018-10-26 CVE-2017-18309 Improper Validation of Array Index vulnerability in Qualcomm SD 845 Firmware and SD 850 Firmware
A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile in version SD 845, SD 850.
local
low complexity
qualcomm CWE-129
7.1