CVE-2018-11874

HIGH

Snapdragon Mobile <SD 835-SDA660 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107681

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (4)
qualcomm/sd_835_firmware
qualcomm/sd_845_firmware
qualcomm/sd_850_firmware
qualcomm/sda660_firmware
Published Oct 29, 2018
Tracked Since Feb 18, 2026