Qualcomm
Qualcomm SD 810 Firmware: vulnerabilidades y CVE
Qualcomm SD 810 Firmware tiene 214 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 138 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE214
Últimos 12 meses0
Críticas138
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2017-11076 | Crítica (9.8) | 0.35% | — | 26 nov 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2017-18279 | Alta (7.8) | 0.22% | — | 6 may 2019 | Lack of check of buffer length before copying can lead to buffer overflow in camera module in Small Cell SoC, Snapdragon Mobile, Snapdragon Wear in FSM9055, FSM9955, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9640, MDM9650,… |
| CVE-2017-18173 | Alta (7.8) | 0.23% | — | 6 may 2019 | In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630,… |
| CVE-2018-5869 | Alta (7.8) | 0.22% | — | 18 ene 2019 | Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415,… |
| CVE-2018-11279 | Alta (8.8) | 0.51% | — | 18 ene 2019 | Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M,… |
| CVE-2017-8276 | Alta (7.8) | 0.19% | — | 18 ene 2019 | Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD… |
| CVE-2017-18330 | Alta (7.8) | 0.18% | — | 3 ene 2019 | Buffer overflow in AES-CCM and AES-GCM encryption via initialization vector in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655,… |
| CVE-2017-18329 | Alta (7.8) | 0.24% | — | 3 ene 2019 | Possible Buffer overflow when transmitting an RTP packet in snapdragon automobile and snapdragon wear in versions MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD… |
| CVE-2017-18326 | Media (5.5) | 0.21% | — | 3 ene 2019 | Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD… |
| CVE-2017-18324 | Media (5.5) | 0.21% | — | 3 ene 2019 | Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205,… |
| CVE-2017-18322 | Media (5.5) | 0.21% | — | 3 ene 2019 | Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD… |
| CVE-2017-18320 | Alta (7.8) | 0.22% | — | 3 ene 2019 | QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429,… |
| CVE-2017-18319 | Media (5.5) | 0.21% | — | 3 ene 2019 | Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425,… |
| CVE-2017-18141 | Alta (7.8) | 0.22% | — | 3 ene 2019 | When a 3rd party TEE has been loaded it is possible for the non-secure world to create a secure monitor call which will give it access to privileged functions meant to only be accessible from the TEE in Snapdragon… |
| CVE-2017-11004 | Media (5.5) | 0.21% | — | 3 ene 2019 | A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD… |
| CVE-2018-5918 | Alta (7.8) | 0.21% | — | 28 nov 2018 | Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU,… |
| CVE-2018-5916 | Media (6.5) | 0.37% | — | 28 nov 2018 | Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M,… |
| CVE-2018-11921 | Alta (7.8) | 0.24% | — | 28 nov 2018 | Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI behavior and create unintended SUI display in Snapdragon Automobile, Snapdragon Mobile and Snapdragon… |
| CVE-2017-18318 | Crítica (9.8) | 1.3% | — | 28 nov 2018 | Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, SD 820A. |
| CVE-2018-11870 | Alta (7.8) | 0.23% | — | 29 oct 2018 | Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number of legacy rates in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206,… |
| CVE-2018-11850 | Alta (7.8) | 0.24% | — | 26 oct 2018 | Lack of check on remaining length parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650,… |
| CVE-2018-11849 | Alta (7.8) | 0.24% | — | 26 oct 2018 | Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9635M,… |
| CVE-2017-18311 | Alta (7.8) | 0.21% | — | 26 oct 2018 | XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unused configuration ports are open in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in… |
| CVE-2017-18310 | Alta (7.8) | 0.24% | — | 26 oct 2018 | ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD… |
| CVE-2017-18124 | Alta (7.8) | 0.22% | — | 26 oct 2018 | During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625,… |
| CVE-2017-18312 | Alta (7.8) | 0.18% | — | 23 oct 2018 | While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to lack of checking of same state transitions in Snapdragon Automobile, Snapdragon Mobile in version… |
| CVE-2017-18304 | Alta (7.8) | 0.26% | — | 23 oct 2018 | Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version FSM9055, MDM9206,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.