|
246501
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to possible stack overflow resulting in memory corru…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12010
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246502
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized paddi…
|
CWE-200
Information Exposure
|
CVE-2018-12006
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246503
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Use-after-free issue in heap while loading audio effects config in audio effects factory.
|
CWE-416
Use After Free
|
CVE-2018-11962
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246504
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_427_firmware sd…
|
While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11899
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246505
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_…
|
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron…
|
CWE-862
Missing Authorization
|
CVE-2018-11888
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246506
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_636_firmware sd_…
|
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11855
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246507
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware qca8081_firmware sd_210_firmware sd_212_firmware
|
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and compromise the whole TEE in Snapdragon Auto, Snap…
|
CWE-20
Improper Input Validation
|
CVE-2018-11847
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246508
|
7.5 |
HIGH
Network
|
apache canonical
|
subversion ubuntu_linux
|
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory li…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2018-11803
|
2024-11-21 12:44 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246509
|
7.8 |
HIGH
Local
|
apache canonical
|
openoffice ubuntu_linux
|
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic …
|
CWE-682
Incorrect Calculation
|
CVE-2018-11790
|
2024-11-21 12:44 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246510
|
7.2 |
HIGH
Network
|
symantec
|
reporter
|
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access c…
|
CWE-78
OS Command
|
CVE-2018-12237
|
2024-11-21 12:44 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|