Vulnerabilities > Qualcomm > Sdx24 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-28 CVE-2018-5917 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm CWE-119
7.8
2018-11-28 CVE-2018-5870 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm SD 835 Firmware, Sda660 Firmware and Sdx24 Firmware
While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA660, SDX24.
local
low complexity
qualcomm CWE-119
7.8
2018-11-28 CVE-2018-11996 Improper Validation of Array Index vulnerability in Qualcomm products
When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 600, SD 820, SD 820A, SD 835, SDA660, SDX20, SDX24.
local
low complexity
qualcomm CWE-129
7.8
2018-11-28 CVE-2018-11994 Unspecified vulnerability in Qualcomm products
SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm
7.8
2018-11-28 CVE-2018-11921 Improper Handling of Exceptional Conditions vulnerability in Qualcomm products
Failure condition is not handled properly and the correct error code is not returned.
local
low complexity
qualcomm CWE-755
7.8
2018-11-28 CVE-2017-18316 Unspecified vulnerability in Qualcomm products
Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130.
local
low complexity
qualcomm
7.8