Qualcomm
Qualcomm SD 617 Firmware: vulnerabilidades y CVE
Qualcomm SD 617 Firmware tiene 177 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 120 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE177
Últimos 12 meses0
Críticas120
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2017-18275 | Media (5.5) | 0.21% | — | 6 may 2019 | A new account can be inserted into simContacts service using Android command line tool in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 425,… |
| CVE-2017-18274 | Alta (7.8) | 0.24% | — | 6 may 2019 | While iterating through the models contained in a fixed-size array in the actData structure, which also stores an incorrect number of models that is greater than the size of the array, a buffer overflow occurs in… |
| CVE-2018-11305 | Alta (7.8) | 0.27% | — | 26 oct 2018 | When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU,… |
| CVE-2017-18310 | Alta (7.8) | 0.24% | — | 26 oct 2018 | ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD… |
| CVE-2017-18124 | Alta (7.8) | 0.22% | — | 26 oct 2018 | During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625,… |
| CVE-2017-18313 | Media (5.3) | 0.26% | — | 23 oct 2018 | Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSS firmware stored in DDR because DXE-accessible memory is located within the… |
| CVE-2017-18312 | Alta (7.8) | 0.18% | — | 23 oct 2018 | While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to lack of checking of same state transitions in Snapdragon Automobile, Snapdragon Mobile in version… |
| CVE-2017-18304 | Alta (7.8) | 0.26% | — | 23 oct 2018 | Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version FSM9055, MDM9206,… |
| CVE-2017-18303 | Alta (7.8) | 0.28% | — | 23 oct 2018 | While processing the sensors registry configuration file, if inputs are not validated a buffer overflow will occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MMDM9206, MDM9607, MDM9650,… |
| CVE-2017-18298 | Alta (7.8) | 0.26% | — | 23 oct 2018 | Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD… |
| CVE-2017-18296 | Alta (7.8) | 0.26% | — | 23 oct 2018 | Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8909W,… |
| CVE-2017-18292 | Media (5.5) | 0.25% | — | 23 oct 2018 | Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD… |
| CVE-2017-18172 | Alta (7.8) | 0.21% | — | 23 oct 2018 | In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting in an Integer Overflow or Wraparound in System UI in Snapdragon Automobile, Snapdragon Mobile in… |
| CVE-2018-5894 | Media (6.5) | 0.84% | — | 6 jul 2018 | Improper Validation of Array Index in Multimedia While parsing an mp4 file in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, an out-of-bounds access can occur. |
| CVE-2018-5882 | Crítica (9.8) | 0.73% | — | 6 jul 2018 | While parsing a Flac file with a corrupted comment block, a buffer over-read can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear. |
| CVE-2018-5876 | Alta (8.8) | 0.82% | — | 6 jul 2018 | While parsing an mp4 file, a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear. |
| CVE-2018-5875 | Alta (8.8) | 0.78% | — | 6 jul 2018 | While parsing an mp4 file, an integer overflow leading to a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear. |
| CVE-2018-5874 | Alta (8.8) | 0.82% | — | 6 jul 2018 | While parsing an mp4 file, a stack-based buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear. |
| CVE-2018-5838 | Alta (7.8) | 0.20% | — | 6 jul 2018 | Improper Validation of Array Index In the adreno OpenGL driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, an out-of-bounds access can occur in SurfaceFlinger. |
| CVE-2018-11259 | Alta (7.7) | 0.20% | — | 6 jul 2018 | Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure… |
| CVE-2017-11088 | Crítica (9.8) | 0.65% | — | 6 jul 2018 | Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 617, SD 625, SD… |
| CVE-2016-10501 | Crítica (9.8) | 1.2% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDM9206, MDM9607, MDM9635M, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD… |
| CVE-2016-10499 | Alta (7.5) | 0.87% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD… |
| CVE-2016-10498 | Crítica (9.8) | 1.2% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD… |
| CVE-2016-10497 | Alta (7.5) | 0.87% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD… |
| CVE-2016-10494 | Crítica (9.8) | 1.3% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9625, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD… |
| CVE-2016-10493 | Crítica (9.8) | 1.1% | — | 18 abr 2018 | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.