Pm855a Firmware
Vendor:
First CVE: Jan 21, 2021 · Active for 5 years
57
Total CVEs
More Total CVEs than 99% of tracked products
57.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Pm855a Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Jun 9, 2021
1,875 days ago
CVE Severity & Scoring
Pm855a Firmware57 CVEs
14%
51%
35%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local23 (40.4%)
Network33 (57.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low53 (93.0%)
High4 (7.0%)
Unknown0 (0.0%)
User Interaction
None57 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low18 (31.6%)
High5 (8.8%)
None34 (59.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1905HIGH Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon | May 7, 2021 | 7.8 | 67 | YES | NO |
CVE-2021-1906MEDIUM Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C | May 7, 2021 | 5.5 | 56 | YES | NO |
CVE-2020-11261HIGH Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Jun 9, 2021 | 7.8 | 55 | YES | NO |
CVE-2020-11188CRITICAL Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag | Mar 17, 2021 | 9.1 | 28 | NO | NO |
CVE-2020-11170CRITICAL Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon | Feb 22, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-11275CRITICAL Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect | Feb 22, 2021 | 9.1 | 27 | NO | NO |
CVE-2020-11182CRITICAL Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago | Jun 9, 2021 | 9.8 | 25 | NO | NO |
CVE-2020-11134CRITICAL Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute inside a NAN management frame ar | Jun 9, 2021 | 9.8 | 24 | NO | NO |
CVE-2021-1927HIGH Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | May 7, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-11279CRITICAL Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd | May 7, 2021 | 9.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
3 CVEs
5.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Pm855a Firmware
Top CWEs
Versions
No cataloged versions.