|
249331
|
7.8 |
HIGH
Local
|
qualcomm
|
msm8996au_firmware sd_410_firmware sd_412_firmware sd_820_firmware sd_820a_firmware
|
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996…
|
CWE-20
Improper Input Validation
|
CVE-2017-18317
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249332
|
7.8 |
HIGH
Local
|
qualcomm
|
sd_600_firmware
|
Buffer over-read vulnerabilities in an older version of ASN.1 parser in Snapdragon Mobile in versions SD 600.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18315
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249333
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_450_firmware sd_…
|
Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210…
|
NVD-CWE-noinfo
|
CVE-2017-18316
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249334
|
5.5 |
MEDIUM
Local
|
google
|
android
|
A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18281
|
2024-11-21 12:19 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249335
|
7.1 |
HIGH
Local
|
qualcomm
|
sd_845_firmware sd_850_firmware
|
A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile in version SD 845, SD 850.
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-18309
|
2024-11-21 12:19 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249336
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware msm8909w_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware
|
Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon Wear in version MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430
|
NVD-CWE-noinfo
|
CVE-2017-18308
|
2024-11-21 12:19 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249337
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware<…
|
XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unused configuration ports are open in Snapdragon Automobile, Snapdragon Mobile, Sna…
|
NVD-CWE-noinfo
|
CVE-2017-18311
|
2024-11-21 12:19 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249338
|
7.8 |
HIGH
Local
|
qualcomm
|
msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_4…
|
ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, S…
|
NVD-CWE-noinfo
|
CVE-2017-18310
|
2024-11-21 12:19 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249339
|
7.8 |
HIGH
Local
|
qualcomm
|
fsm9055_firmware ipq4019_firmware mdm9206_firmware mdm9607_firmware mdm9625_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9650_firmware mdm9655_firmware
|
During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18124
|
2024-11-21 12:19 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249340
|
9.8 |
CRITICAL
Network
|
pippo alibaba
|
pippo fastjson
|
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a…
|
CWE-20
Improper Input Validation
|
CVE-2017-18349
|
2024-11-21 12:19 |
2018-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|