Sd8c
Vendor:
First CVE: Jan 21, 2021 · Active for 5 years
160
Total CVEs
More Total CVEs than 98% of tracked products
160.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 70% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sd8c over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Nov 12, 2021
1,716 days ago
CVE Severity & Scoring
Sd8c160 CVEs
16%
57%
26%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local77 (48.1%)
Network78 (48.8%)
Unknown0 (0.0%)
Physical1 (0.6%)
Adjacent Network4 (2.5%)
Attack Complexity
Low154 (96.3%)
High6 (3.8%)
Unknown0 (0.0%)
User Interaction
None159 (99.4%)
Unknown0 (0.0%)
Required1 (0.6%)
Privileges Required
Low63 (39.4%)
High12 (7.5%)
None85 (53.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (160 CVEs).
160 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1905HIGH Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon | May 7, 2021 | 7.8 | 67 | YES | NO |
CVE-2021-1906MEDIUM Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C | May 7, 2021 | 5.5 | 56 | YES | NO |
CVE-2020-11261HIGH Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Jun 9, 2021 | 7.8 | 55 | YES | NO |
CVE-2021-1975CRITICAL Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO | Nov 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1972CRITICAL Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1920CRITICAL Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1919CRITICAL Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-3686CRITICAL Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdrag | Jan 21, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1946CRITICAL Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-11301HIGH Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect | Sep 8, 2021 | 7.5 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (160 CVEs).
CISA KEV
3 CVEs
1.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (160 CVEs).
Media Mentions
Signals from CVEs in this product scope (160 CVEs).
Top CNAs Publishing CVEs For Sd8c
Top CWEs
Versions
No cataloged versions.