CVE-2018-5868

HIGH

Qualcomm Snapdragon Firmware - Buffer Overflow in WideVine via Input Size Mismatch

Title source: llm
STIX 2.1

Description

Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106128

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (16)
qualcomm/msm8996au_firmware
qualcomm/sd_425_firmware
qualcomm/sd_430_firmware
qualcomm/sd_450_firmware
qualcomm/sd_625_firmware
qualcomm/sd_670_firmware
qualcomm/sd_710_firmware
qualcomm/sd_712_firmware
qualcomm/sd_820_firmware
qualcomm/sd_820a_firmware
... and 6 more
Published Jan 18, 2019
Tracked Since Feb 18, 2026