CVE-2018-11858

HIGH

Snapdragon Mobile <SD 850 - Buffer Overflow

Title source: llm
STIX 2.1

Description

When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
qualcomm/sd_835_firmware
qualcomm/sd_845_firmware
qualcomm/sd_850_firmware
Published Oct 29, 2018
Tracked Since Feb 18, 2026