Msm8940
Vendor:
First CVE: Nov 21, 2019 · Active for 6 years
233
Total CVEs
More Total CVEs than 100% of tracked products
46.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Msm8940 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2019
6 years ago
Most Recent CVE
Aug 8, 2023
1,084 days ago
CVE Severity & Scoring
Msm8940233 CVEs
10%
44%
46%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local99 (42.5%)
Network133 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low226 (97.0%)
High7 (3.0%)
Unknown0 (0.0%)
User Interaction
None233 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low97 (41.6%)
High3 (1.3%)
None133 (57.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (233 CVEs).
233 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11261HIGH Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Jun 9, 2021 | 7.8 | 55 | YES | NO |
CVE-2022-25718CRITICAL Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connec | Oct 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-14062CRITICAL Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum | Jun 22, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-14005CRITICAL Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon | Jan 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-10532CRITICAL Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Sna | Jan 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-10500CRITICAL While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, | Dec 18, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-1975CRITICAL Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO | Nov 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1920CRITICAL Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1919CRITICAL Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-3686CRITICAL Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdrag | Jan 21, 2021 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (233 CVEs).
CISA KEV
1 CVE
0.4% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (233 CVEs).
Media Mentions
Signals from CVEs in this product scope (233 CVEs).
Top CNAs Publishing CVEs For Msm8940
Top CWEs
Versions
No cataloged versions.