|
246441
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware qcs605_firmware sd_410_firmware sd_412_firmware sd_636_firmware sd_712_firmware sd_710_firmware sd_67…
|
TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap…
|
NVD-CWE-noinfo
|
CVE-2018-11970
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246442
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware sd_210_firmware
|
Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearable…
|
CWE-20
Improper Input Validation
|
CVE-2018-11966
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246443
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_410_firmware sd_412_firmware sd_820a_firmware
|
Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM920…
|
CWE-20
Improper Input Validation
|
CVE-2018-11830
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246444
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware qm215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425…
|
Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sna…
|
NVD-CWE-noinfo
|
CVE-2018-11958
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246445
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk_ii
|
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12183
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246446
|
6.7 |
MEDIUM
Local
|
tianocore
|
edk_ii
|
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local acce…
|
CWE-441
Confused Deputy
|
CVE-2018-12182
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246447
|
6.0 |
MEDIUM
Local
|
tianocore
|
edk_ii
|
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12181
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246448
|
8.8 |
HIGH
Network
|
tianocore opensuse
|
edk_ii leap
|
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12180
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246449
|
7.8 |
HIGH
Local
|
tianocore
|
edk_ii
|
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
|
NVD-CWE-noinfo
|
CVE-2018-12179
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246450
|
9.1 |
CRITICAL
Network
|
tianocore
|
edk_ii
|
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12178
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|