|
249811
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware qca8081_firmware qcs605_firmware
|
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Cons…
|
NVD-CWE-noinfo
|
CVE-2018-11820
|
2024-11-21 12:44 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249812
|
5.5 |
MEDIUM
Local
|
intel
|
proset\/wireless
|
Buffer overflow in the command-line interface for Intel(R) PROSet Wireless v20.50 and before may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12159
|
2024-11-21 12:44 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249813
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT modul…
|
CWE-476 CWE-416
NULL Pointer Dereference Use After Free
|
CVE-2018-12014
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249814
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2018-12011
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249815
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to possible stack overflow resulting in memory corru…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12010
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249816
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized paddi…
|
CWE-200
Information Exposure
|
CVE-2018-12006
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249817
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Use-after-free issue in heap while loading audio effects config in audio effects factory.
|
CWE-416
Use After Free
|
CVE-2018-11962
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249818
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_427_firmware sd…
|
While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11899
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249819
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_…
|
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron…
|
CWE-862
Missing Authorization
|
CVE-2018-11888
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249820
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_636_firmware sd_…
|
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11855
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|