|
247931
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_…
|
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron…
|
CWE-862
Missing Authorization
|
CVE-2018-11888
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247932
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_636_firmware sd_…
|
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11855
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247933
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware qca8081_firmware sd_210_firmware sd_212_firmware
|
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and compromise the whole TEE in Snapdragon Auto, Snap…
|
CWE-20
Improper Input Validation
|
CVE-2018-11847
|
2024-11-21 12:44 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247934
|
7.5 |
HIGH
Network
|
apache canonical
|
subversion ubuntu_linux
|
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory li…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2018-11803
|
2024-11-21 12:44 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247935
|
7.8 |
HIGH
Local
|
apache canonical
|
openoffice ubuntu_linux
|
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic …
|
CWE-682
Incorrect Calculation
|
CVE-2018-11790
|
2024-11-21 12:44 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247936
|
7.2 |
HIGH
Network
|
symantec
|
reporter
|
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access c…
|
CWE-78
OS Command
|
CVE-2018-12237
|
2024-11-21 12:44 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247937
|
8.8 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware
|
Improper check while accessing the local memory stack on MQTT connection request can lead to buffer overflow in snapdragon wear in versions MDM9206, MDM9607
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11993
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247938
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware …
|
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996A…
|
CWE-20
Improper Input Validation
|
CVE-2018-11999
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247939
|
7.5 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_427_firmware sd_435_firmware sd_450_firmware sd_625_firmware sd_636_firmware sd_835_…
|
While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 2…
|
CWE-362
Race Condition
|
CVE-2018-11998
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247940
|
7.8 |
HIGH
Local
|
intel
|
proset\/wireless_software
|
Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized user to potentially enable escalation of privilege …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12177
|
2024-11-21 12:44 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|