Pm8150 Firmware
Vendor:
First CVE: Jan 21, 2021 · Active for 5 years
67
Total CVEs
More Total CVEs than 99% of tracked products
67.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
4.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Pm8150 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Jun 9, 2021
1,875 days ago
CVE Severity & Scoring
Pm8150 Firmware67 CVEs
13%
55%
31%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local29 (43.3%)
Network36 (53.7%)
Unknown0 (0.0%)
Physical1 (1.5%)
Adjacent Network1 (1.5%)
Attack Complexity
Low65 (97.0%)
High2 (3.0%)
Unknown0 (0.0%)
User Interaction
None66 (98.5%)
Unknown0 (0.0%)
Required1 (1.5%)
Privileges Required
Low24 (35.8%)
High5 (7.5%)
None38 (56.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1905HIGH Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon | May 7, 2021 | 7.8 | 67 | YES | NO |
CVE-2021-1906MEDIUM Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C | May 7, 2021 | 5.5 | 56 | YES | NO |
CVE-2020-11261HIGH Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Jun 9, 2021 | 7.8 | 55 | YES | NO |
CVE-2020-11188CRITICAL Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag | Mar 17, 2021 | 9.1 | 28 | NO | NO |
CVE-2020-11170CRITICAL Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon | Feb 22, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-11275CRITICAL Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect | Feb 22, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-1915HIGH Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Elec | May 7, 2021 | 7.8 | 26 | NO | NO |
CVE-2020-11182CRITICAL Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago | Jun 9, 2021 | 9.8 | 25 | NO | NO |
CVE-2020-11240HIGH Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy of the user argument in Snapdragon Auto, S | Jun 9, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-11134CRITICAL Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute inside a NAN management frame ar | Jun 9, 2021 | 9.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (67 CVEs).
CISA KEV
3 CVEs
4.5% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (67 CVEs).
Media Mentions
Signals from CVEs in this product scope (67 CVEs).
Top CNAs Publishing CVEs For Pm8150 Firmware
Top CWEs
Versions
No cataloged versions.