7.8
CVE-2018-11267
- EPSS 0.04%
- Veröffentlicht 20.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:01
- Quelle product-security@qualcomm.com
- Teams Watchlist Login
- Unerledigt Login
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9615, MDM9640, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016, when sending an malformed XML data to deviceprogrammer/firehose it may do an out of bounds buffer write allowing a region of memory to be filled with 0x20.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm9206 Firmware Version-
Qualcomm ≫ Mdm9607 Firmware Version-
Qualcomm ≫ Mdm9615 Firmware Version-
Qualcomm ≫ Mdm9640 Firmware Version-
Qualcomm ≫ Mdm9650 Firmware Version-
Qualcomm ≫ Mdm9655 Firmware Version-
Qualcomm ≫ Msm8996au Firmware Version-
Qualcomm ≫ Sd210 Firmware Version-
Qualcomm ≫ Sd212 Firmware Version-
Qualcomm ≫ Sd205 Firmware Version-
Qualcomm ≫ Sd410 Firmware Version-
Qualcomm ≫ Sd412 Firmware Version-
Qualcomm ≫ Sd425 Firmware Version-
Qualcomm ≫ Sd427 Firmware Version-
Qualcomm ≫ Sd430 Firmware Version-
Qualcomm ≫ Sd435 Firmware Version-
Qualcomm ≫ Sd450 Firmware Version-
Qualcomm ≫ Sd600 Firmware Version-
Qualcomm ≫ Sd615 Firmware Version-
Qualcomm ≫ Sd616 Firmware Version-
Qualcomm ≫ Sd415 Firmware Version-
Qualcomm ≫ Sd617 Firmware Version-
Qualcomm ≫ Sd625 Firmware Version-
Qualcomm ≫ Sd650 Firmware Version-
Qualcomm ≫ Sd652 Firmware Version-
Qualcomm ≫ Sd820 Firmware Version-
Qualcomm ≫ Sd820a Firmware Version-
Qualcomm ≫ Sd835 Firmware Version-
Qualcomm ≫ Sd845 Firmware Version-
Qualcomm ≫ Sd850 Firmware Version-
Qualcomm ≫ Sda660 Firmware Version-
Qualcomm ≫ Sdm429 Firmware Version-
Qualcomm ≫ Sdm439 Firmware Version-
Qualcomm ≫ Sdm630 Firmware Version-
Qualcomm ≫ Sdm632 Firmware Version-
Qualcomm ≫ Sdm636 Firmware Version-
Qualcomm ≫ Sdm660 Firmware Version-
Qualcomm ≫ Sdx20 Firmware Version-
Qualcomm ≫ Snapdragon High Med 2016 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.08 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.