ZeroHour

CVE-2018-11267

CVSS 3.0
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9615, MDM9640, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016, when sending an malformed XML data to deviceprogrammer/firehose it may do an out of bounds buffer write allowing a region of memory to be filled with 0x20.

Vendors
qualcomm
Products
mdm9206 firmware, mdm9607 firmware, mdm9615 firmware, mdm9640 firmware, mdm9650 firmware, mdm9655 firmware, msm8996au firmware, sd210 firmware, sd212 firmware, sd205 firmware, sd410 firmware, sd412 firmware
Weakness
CWE-129
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.