CVE-2017-18294
—CVSS 3.0
7.8 high
EPSS
<1%p18
Published
()
Modified
Description
While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size of ELF64 header size in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDA660, SDX20.
- Vendors
- qualcomm
- Products
- fsm9055 firmware, mdm9206 firmware, mdm9607 firmware, mdm9650 firmware, msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 425 firmware, sd 430 firmware, sd 450 firmware
- Weakness
- CWE-125
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.