Qualcomm
Qualcomm SD 412 Firmware: vulnerabilidades y CVE
Qualcomm SD 412 Firmware tiene 240 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 131 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE240
Últimos 12 meses0
Críticas131
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-2275 | Media (5.5) | 0.19% | — | 6 nov 2019 | While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key operations are invoked(Depends on CVE-2018-13907) in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-2294 | Crítica (9.8) | 0.91% | — | 30 sept 2019 | Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-2241 | Media (5.5) | 0.18% | — | 25 jul 2019 | While rendering the layout background, Error status check is not caught properly and also incorrect status handling is being done leading to unintended SUI behaviour in Snapdragon Auto, Snapdragon Compute, Snapdragon… |
| CVE-2019-2239 | Media (5.5) | 0.18% | — | 25 jul 2019 | Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2019-2238 | Alta (7.8) | 0.19% | — | 25 jul 2019 | Lack of check of data type can lead to subsequent loop-expression potentially go negative and the condition will still evaluate to true leading to buffer underflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon… |
| CVE-2019-2237 | Media (5.5) | 0.18% | — | 25 jul 2019 | Failure in taking appropriate action to handle the error case If keypad gpio deactivation fails leads to silent failure scenario and subsequent logic gets executed everytime in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-2236 | Media (5.5) | 0.19% | — | 25 jul 2019 | Null pointer dereference during secure application termination using specific application ids. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon… |
| CVE-2019-2235 | Alta (7.8) | 0.21% | — | 25 jul 2019 | Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2018-13927 | Alta (7.8) | 0.18% | — | 22 jul 2019 | Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer… |
| CVE-2018-13896 | Alta (7.8) | 0.21% | — | 22 jul 2019 | XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage.. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2018-5913 | Alta (7.8) | 0.21% | — | 14 jun 2019 | A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2018-13910 | Alta (7.8) | 0.21% | — | 14 jun 2019 | Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2018-13909 | Alta (7) | 0.14% | — | 14 jun 2019 | Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulting in unexpected behavior in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics… |
| CVE-2018-13908 | Alta (7.8) | 0.19% | — | 14 jun 2019 | Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2018-13907 | Media (5.3) | 0.66% | — | 14 jun 2019 | While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if any key operations are invoked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2018-13906 | Crítica (9.1) | 0.66% | — | 14 jun 2019 | The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2018-13898 | Crítica (9.8) | 0.73% | — | 14 jun 2019 | Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2017-8252 | Media (5.5) | 0.22% | — | 14 jun 2019 | Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2018-13886 | Crítica (9.8) | 1.1% | — | 24 may 2019 | Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2018-12013 | Alta (7.8) | 0.21% | — | 24 may 2019 | Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2018-12012 | Alta (7.8) | 0.21% | — | 24 may 2019 | While updating blacklisting region shared buffered memory region is not validated against newly updated black list, causing boot-up to be compromised in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer… |
| CVE-2018-12004 | Media (5.5) | 0.20% | — | 24 may 2019 | Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2018-11976 | Media (5.5) | 0.20% | — | 24 may 2019 | ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2017-18131 | Alta (7.8) | 0.23% | — | 6 may 2019 | In QTEE, an incorrect fuse value can be blown in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450,… |
| CVE-2017-15841 | Media (5.5) | 0.18% | — | 6 may 2019 | When HOST sends a Special command ID packet, Controller triggers a RAM Dump and FW reset in Snapdragon Mobile in version SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD… |
| CVE-2018-11971 | Media (5.5) | 0.20% | — | 4 abr 2019 | Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity,… |
| CVE-2018-11970 | Alta (7.8) | 0.21% | — | 4 abr 2019 | TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in… |
| CVE-2018-11958 | Media (5.5) | 0.20% | — | 4 abr 2019 | Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2018-11830 | Alta (7.8) | 0.21% | — | 4 abr 2019 | Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650,… |
| CVE-2018-11948 | Media (5.5) | 0.21% | — | 25 feb 2019 | Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose continuity in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer… |