CVE-2018-13914

Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 636, SD 820A, SD 835, SDM630, SDM660, SDX20.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
qualcommsnapdragon_auto_firmware
-
qualcommsnapdragon_consumer_internet_of_things_firmware
-
qualcommsnapdragon_industrial_internet_of_things_firmware
-
qualcommmdm9150_firmware
-
qualcommmdm9206_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8996au_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommsd_636_firmware
-
qualcommsd_820a_firmware
-
qualcommsd_835_firmware
-
qualcommsdm630_firmware
-
qualcommsdm660_firmware
-
qualcommsdx20_firmware
-
𝑥
= Vulnerable software versions