Vulnerabilities > Qualcomm > SD 850 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-28 CVE-2018-11994 Unspecified vulnerability in Qualcomm products
SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm
7.8
2018-11-28 CVE-2018-11921 Improper Handling of Exceptional Conditions vulnerability in Qualcomm products
Failure condition is not handled properly and the correct error code is not returned.
local
low complexity
qualcomm CWE-755
7.8
2018-11-28 CVE-2017-18316 Unspecified vulnerability in Qualcomm products
Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm
7.8
2018-10-29 CVE-2018-11884 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11882 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11880 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11877 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11876 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11875 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm SD 845 Firmware and SD 850 Firmware
Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.
local
low complexity
qualcomm CWE-119
7.8
2018-10-29 CVE-2018-11874 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
local
low complexity
qualcomm CWE-119
7.8