Pm439 Firmware
Vendor:
First CVE: Feb 22, 2021 · Active for 5 years
42
Total CVEs
More Total CVEs than 98% of tracked products
42.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 74% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Pm439 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2021
5 years ago
Most Recent CVE
Jun 9, 2021
1,874 days ago
CVE Severity & Scoring
Pm439 Firmware42 CVEs
12%
48%
40%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local22 (52.4%)
Network19 (45.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.4%)
Attack Complexity
Low38 (90.5%)
High4 (9.5%)
Unknown0 (0.0%)
User Interaction
None42 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low19 (45.2%)
High2 (4.8%)
None21 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1905HIGH Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon | May 7, 2021 | 7.8 | 67 | YES | NO |
CVE-2021-1906MEDIUM Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C | May 7, 2021 | 5.5 | 56 | YES | NO |
CVE-2020-11261HIGH Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Jun 9, 2021 | 7.8 | 55 | YES | NO |
CVE-2021-1910CRITICAL Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, S | May 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-11299CRITICAL Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industri | Mar 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-11188CRITICAL Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag | Mar 17, 2021 | 9.1 | 28 | NO | NO |
CVE-2020-11170CRITICAL Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon | Feb 22, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-11240HIGH Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy of the user argument in Snapdragon Auto, S | Jun 9, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-1927HIGH Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | May 7, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-1895HIGH Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music | May 7, 2021 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (42 CVEs).
CISA KEV
3 CVEs
7.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (42 CVEs).
Media Mentions
Signals from CVEs in this product scope (42 CVEs).
Top CNAs Publishing CVEs For Pm439 Firmware
Top CWEs
Versions
No cataloged versions.