Pm8952 Firmware
Vendor:
First CVE: Jan 21, 2021 · Active for 5 years
26
Total CVEs
More Total CVEs than 96% of tracked products
26.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pm8952 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Jun 9, 2021
1,875 days ago
CVE Severity & Scoring
Pm8952 Firmware26 CVEs
35%
58%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (23.1%)
Network19 (73.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.8%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (23.1%)
High0 (0.0%)
None20 (76.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11188CRITICAL Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag | Mar 17, 2021 | 9.1 | 28 | NO | NO |
CVE-2020-11170CRITICAL Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon | Feb 22, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-11279CRITICAL Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd | May 7, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-11227CRITICAL Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi | Mar 17, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-11192CRITICAL Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd | Mar 17, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-11272CRITICAL Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Sna | Feb 22, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-11159CRITICAL Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdrago | Jun 9, 2021 | 9.1 | 22 | NO | NO |
CVE-2020-11285CRITICAL Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, | May 7, 2021 | 9.1 | 22 | NO | NO |
CVE-2020-11251CRITICAL Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, | Apr 7, 2021 | 9.1 | 22 | NO | NO |
CVE-2020-11191CRITICAL Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Elect | Apr 7, 2021 | 9.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Pm8952 Firmware
Top CWEs
Versions
No cataloged versions.