CVE-2018-11830

HIGH

Qualcomm MDM9206/9607/9650/9655, MSM8996AU, SD 410/12/820A Firmware Integer Overflow

Title source: llm
STIX 2.1

Description

Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 410/12, SD 820A

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (8)
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/mdm9650_firmware
qualcomm/mdm9655_firmware
qualcomm/msm8996au_firmware
qualcomm/sd_410_firmware
qualcomm/sd_412_firmware
qualcomm/sd_820a_firmware
Published Apr 04, 2019
Tracked Since Feb 18, 2026