Msm8976 Firmware
Vendor:
First CVE: Apr 18, 2018 · Active for 8 years
80
Total CVEs
More Total CVEs than 99% of tracked products
13.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Msm8976 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2018
8 years ago
Most Recent CVE
Mar 10, 2023
1,236 days ago
CVE Severity & Scoring
Msm8976 Firmware80 CVEs
9%
46%
45%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local27 (33.8%)
Network49 (61.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (5.0%)
Attack Complexity
Low80 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None80 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low28 (35.0%)
High0 (0.0%)
None52 (65.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (80 CVEs).
80 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25718CRITICAL Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connec | Oct 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-25748CRITICAL Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Oct 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-25720CRITICAL Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics C | Oct 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-25687CRITICAL memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indus | Oct 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-1975CRITICAL Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO | Nov 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1920CRITICAL Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1919CRITICAL Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-10511CRITICAL Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, | Dec 12, 2019 | 9.8 | 30 | NO | NO |
CVE-2016-10442CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or k | Apr 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2021-30284CRITICAL Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna | Nov 12, 2021 | 9.1 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (80 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (80 CVEs).
Media Mentions
Signals from CVEs in this product scope (80 CVEs).
Top CNAs Publishing CVEs For Msm8976 Firmware
Top CWEs
Versions
No cataloged versions.