Sd850
Vendor:
First CVE: Apr 11, 2018 · Active for 8 years
468
Total CVEs
More Total CVEs than 99% of tracked products
78.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sd850 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2018
8 years ago
Most Recent CVE
Nov 26, 2024
606 days ago
CVE Severity & Scoring
Sd850468 CVEs
13%
52%
34%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local233 (49.8%)
Network222 (47.4%)
Unknown0 (0.0%)
Physical2 (0.4%)
Adjacent Network11 (2.4%)
Attack Complexity
Low458 (97.9%)
High10 (2.1%)
Unknown0 (0.0%)
User Interaction
None465 (99.4%)
Unknown0 (0.0%)
Required3 (0.6%)
Privileges Required
Low230 (49.1%)
High3 (0.6%)
None235 (50.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (468 CVEs).
468 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10529HIGH Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdr | Nov 6, 2019 | 8.1 | 33 | NO | YES |
CVE-2018-11945CRITICAL Improper input validation in wireless service messaging module for data received from broadcast messages can lead to heap overflow in Snapdragon Auto, Snapdragon Compute, Snapdrago | Feb 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-10538CRITICAL Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdrag | Sep 30, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-2276CRITICAL Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consum | Jul 25, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-13924CRITICAL Lack of check to prevent the buffer length taking negative values can lead to stack overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, | Jul 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-13886CRITICAL Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon | May 24, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-18160CRITICAL AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM | Jan 18, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-25748CRITICAL Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Oct 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-1975CRITICAL Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO | Nov 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1980CRITICAL Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electron | Oct 20, 2021 | 9.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (468 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.2% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (468 CVEs).
Media Mentions
Signals from CVEs in this product scope (468 CVEs).
Top CNAs Publishing CVEs For Sd850
Top CWEs
Versions
No cataloged versions.