7.8
CVE-2018-11816
- EPSS 0.03%
- Published 26.11.2024 14:15:17
- Last modified 06.02.2025 16:41:05
- Source product-security@qualcomm.com
- Teams watchlist Login
- Open Login
Crafted Binder Request Causes Heap UAF in MediaServer
Data is provided by the National Vulnerability Database (NVD)
Qualcomm ≫ 9206 Lte Modem Firmware Version-
Qualcomm ≫ Apq8016 Firmware Version-
Qualcomm ≫ Apq8017 Firmware Version-
Qualcomm ≫ Apq8039 Firmware Version-
Qualcomm ≫ Apq8052 Firmware Version-
Qualcomm ≫ Apq8056 Firmware Version-
Qualcomm ≫ Apq8076 Firmware Version-
Qualcomm ≫ Aqt1000 Firmware Version-
Qualcomm ≫ Ar6003 Firmware Version-
Qualcomm ≫ Sd660 Firmware Version-
Qualcomm ≫ Sd670 Firmware Version-
Qualcomm ≫ Sd820 Firmware Version-
Qualcomm ≫ Sd821 Firmware Version-
Qualcomm ≫ Sd835 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.051 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
product-security@qualcomm.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.