CVE-2018-11872

HIGH

Snapdragon Mobile <SD 845-SDA660 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107681

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
qualcomm/sd_845_firmware
qualcomm/sd_850_firmware
qualcomm/sda660_firmware
Published Oct 29, 2018
Tracked Since Feb 18, 2026