CVE-2018-11866

HIGH

Snapdragon Mobile/Snapdragon Wear - Integer Overflow

Title source: llm
STIX 2.1

Description

Integer overflow may happen in WLAN when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (25)
qualcomm/ipq8074_firmware
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/mdm9650_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
qualcomm/sd_212_firmware
qualcomm/sd_425_firmware
qualcomm/sd_427_firmware
qualcomm/sd_430_firmware
... and 15 more
Published Oct 29, 2018
Tracked Since Feb 18, 2026