CVE-2018-11938 PUBLISHED CVSS 4.599999904632568 MEDIUM

Improper input validation for argument received from HLOS can lead to buffer overflows and unexpected behavior in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCA8081, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130.

EPSS 0.06% · 19.3th percentile

Risk Scores

CVSS v2.0
4.599999904632568
EPSS Score
0.06%
19.3th percentile

Affected Products

VendorProductVersions
qualcommsd_835_firmware
qualcommsd_632_firmware
qualcommsd_415_firmware
qualcommsdm630_firmware
qualcommsd_636_firmware
qualcommsd_16_firmware
qualcommmsm8909w_firmware
qualcommsd_710_firmware
qualcommmdm9650_firmware
qualcommipq8074_firmware
qualcommsd_410_firmware
qualcommsd_8cx_firmware
qualcommsd_675_firmware
qualcommsd_850_firmware
qualcommsd_439_firmware
qualcommsd_820a_firmware
qualcommsd_205_firmware
qualcommsda660_firmware
qualcommsdm439_firmware
qualcommmdm9206_firmware

…and 26 more

Timeline

References

Open in Interactive Console →