CVE-2018-11856

HIGH

Snapdragon Mobile <SD 850 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 835, SD 845, SD 850.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107681

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
qualcomm/sd_835_firmware
qualcomm/sd_845_firmware
qualcomm/sd_850_firmware
Published Oct 29, 2018
Tracked Since Feb 18, 2026