CVE-2018-11870

HIGH

Snapdragon Automobile/Mobile/Wear <various - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number of legacy rates in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107681

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (30)
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/mdm9635m_firmware
qualcomm/mdm9640_firmware
qualcomm/mdm9650_firmware
qualcomm/msm8996au_firmware
qualcomm/qca4531_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6574au_firmware
qualcomm/qca6584_firmware
... and 20 more
Published Oct 29, 2018
Tracked Since Feb 18, 2026