CVE-2018-13912
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
25/02/2019
Last modified:
26/02/2019
Description
Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:qualcomm:snapdragon_auto_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_auto:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:snapdragon_connectivity_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_connectivity:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:snapdragon_consumer_internet_of_things_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_consumer_internet_of_things:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:snapdragon_industrial_internet_of_things_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_industrial_internet_of_things:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:snapdragon_mobile_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_mobile:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:snapdragon_voice_\&_music_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:snapdragon_voice_\&_music:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:mdm9150_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:mdm9150:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



