|
249491
|
7.8 |
HIGH
Local
|
qualcomm
|
msm8996au_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_435_firmware sd_439_firmware sd_429_firmware sd_450_firmware sd_615…
|
QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 410/12, SD 425, SD 427, SD 430, SD 4…
|
CWE-20
Improper Input Validation
|
CVE-2017-18320
|
2024-11-21 12:19 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249492
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9615_firmware mdm9625_firmware mdm9635m_firmware mdm9645_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware sd_210_firmware
|
Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205…
|
CWE-320
Key Management Errors
|
CVE-2017-18319
|
2024-11-21 12:19 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249493
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware
|
When a 3rd party TEE has been loaded it is possible for the non-secure world to create a secure monitor call which will give it access to privileged functions meant to only be accessible from the TEE…
|
NVD-CWE-noinfo
|
CVE-2017-18141
|
2024-11-21 12:19 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249494
|
7.5 |
HIGH
Network
|
google
|
rendertron
|
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
|
CWE-200
Information Exposure
|
CVE-2017-18355
|
2024-11-21 12:19 |
2018-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249495
|
7.5 |
HIGH
Network
|
google
|
rendertron
|
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
|
CWE-22
Path Traversal
|
CVE-2017-18354
|
2024-11-21 12:19 |
2018-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249496
|
7.5 |
HIGH
Network
|
google
|
rendertron
|
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote…
|
NVD-CWE-noinfo
|
CVE-2017-18353
|
2024-11-21 12:19 |
2018-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249497
|
6.1 |
MEDIUM
Network
|
google
|
rendertron
|
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18352
|
2024-11-21 12:19 |
2018-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249498
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8996au_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_430_firmware sd_450_firmware sd_625_firmware sd_650_firmware sd_652_firmware sd_810_firmware sd_820…
|
Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, SD 820A.
|
CWE-20
Improper Input Validation
|
CVE-2017-18318
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249499
|
7.8 |
HIGH
Local
|
qualcomm
|
msm8996au_firmware sd_410_firmware sd_412_firmware sd_820_firmware sd_820a_firmware
|
Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivation flow sequence in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996…
|
CWE-20
Improper Input Validation
|
CVE-2017-18317
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249500
|
7.8 |
HIGH
Local
|
qualcomm
|
sd_600_firmware
|
Buffer over-read vulnerabilities in an older version of ASN.1 parser in Snapdragon Mobile in versions SD 600.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18315
|
2024-11-21 12:19 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|