Sd8c Firmware

Vendor:

First CVE: Jan 21, 2021 · Active for 5 years

136
Total CVEs
More Total CVEs than 98% of tracked products
136.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sd8c Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2021
5 years ago
Most Recent CVE
Nov 12, 2021
1,719 days ago

CVE Severity & Scoring

Sd8c Firmware136 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local71 (52.2%)
Network60 (44.1%)
Unknown0 (0.0%)
Physical1 (0.7%)
Adjacent Network4 (2.9%)
Attack Complexity
Low131 (96.3%)
High5 (3.7%)
Unknown0 (0.0%)
User Interaction
None135 (99.3%)
Unknown0 (0.0%)
Required1 (0.7%)
Privileges Required
Low59 (43.4%)
High10 (7.4%)
None67 (49.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (136 CVEs).

136 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon
May 7, 20217.867YESNO
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon C
May 7, 20215.556YESNO
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv
Jun 9, 20217.855YESNO
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO
Nov 12, 20219.830NONO
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap
Sep 8, 20219.830NONO
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I
Sep 8, 20219.830NONO
Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer
Sep 8, 20219.830NONO
Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer
Sep 9, 20219.829NONO
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect
Sep 8, 20217.529NONO
UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdr
Sep 9, 20219.828NONO

Exploit Exposure

Signals from CVEs in this product scope (136 CVEs).

CISA KEV
3 CVEs
2.2% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (136 CVEs).

Media Mentions

Signals from CVEs in this product scope (136 CVEs).

Top CNAs Publishing CVEs For Sd8c Firmware

Top CWEs

Versions

No cataloged versions.