Pm8952 Firmware

Vendor:

First CVE: Jan 21, 2021 · Active for 5 years

26
Total CVEs
More Total CVEs than 96% of tracked products
26.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pm8952 Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Jun 9, 2021
1,875 days ago

CVE Severity & Scoring

Pm8952 Firmware26 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local6 (23.1%)
Network19 (73.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.8%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (23.1%)
High0 (0.0%)
None20 (76.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag
Mar 17, 20219.128NONO
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon
Feb 22, 20219.828NONO
Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd
May 7, 20219.824NONO
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
Mar 17, 20219.824NONO
Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd
Mar 17, 20219.824NONO
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Sna
Feb 22, 20219.824NONO
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdrago
Jun 9, 20219.122NONO
Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
May 7, 20219.122NONO
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
Apr 7, 20219.122NONO
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Elect
Apr 7, 20219.122NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Pm8952 Firmware

Top CWEs

Versions

No cataloged versions.