
CVE-2018-11888
https://notcve.org/view.php?id=CVE-2018-11888
11 Feb 2019 — Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Voice & Music in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD ... • http://www.securityfocus.com/bid/106475 • CWE-862: Missing Authorization •

CVE-2018-11847
https://notcve.org/view.php?id=CVE-2018-11847
11 Feb 2019 — Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and compromise the whole TEE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9206, MDM9607, MD... • http://www.securityfocus.com/bid/106475 • CWE-20: Improper Input Validation •

CVE-2018-11855
https://notcve.org/view.php?id=CVE-2018-11855
11 Feb 2019 — If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM630, SDM660. Si un usuario final emplea un código OCE de mues... • https://www.qualcomm.com/company/product-security/bulletins • CWE-190: Integer Overflow or Wraparound •

CVE-2018-5867
https://notcve.org/view.php?id=CVE-2018-5867
18 Jan 2019 — Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016, SXR1130 Lalta de comprobación del tamaño de las entra... • http://www.securityfocus.com/bid/106128 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-18332
https://notcve.org/view.php?id=CVE-2017-18332
18 Jan 2019 — Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130 Se registran claves de seguridad cuando cualquier llamada WCDMA se configura/reconfigura en snapdragon automobile, snapdragon mob... • http://www.securityfocus.com/bid/106128 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-11288
https://notcve.org/view.php?id=CVE-2018-11288
18 Jan 2019 — Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended region in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDX24, SXR1130 Un posible comportamiento sin definir debido a la falta de una comprobación de tamaño en "function" para el parámetro "segment_idx"... • https://www.qualcomm.com/company/product-security/bulletins • CWE-129: Improper Validation of Array Index •

CVE-2018-11999
https://notcve.org/view.php?id=CVE-2018-11999
18 Jan 2019 — Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM630, SDM660, SDX24 Validación de entradas incorrecta en trustzone puede provocar una denegación de servicio (DoS) en snapdragon automobile, snapdragon mobile y snapdragon wear en las versiones MDM9206, MDM9607, MDM96... • http://www.securityfocus.com/bid/106128 • CWE-20: Improper Input Validation •

CVE-2017-18160
https://notcve.org/view.php?id=CVE-2017-18160
18 Jan 2019 — AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850 Fallo de sesión AGPS en el módulo GNSS debido a que los conjuntos de cifrado están embebidos y que cada vez necesitaban ser actualizados manualmente en snapdragon mobile y snapdragon wear en sus versiones MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845 y SD 850. • http://www.securityfocus.com/bid/106128 • CWE-310: Cryptographic Issues •

CVE-2018-11279
https://notcve.org/view.php?id=CVE-2018-11279
18 Jan 2019 — Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 810, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660... • http://www.securityfocus.com/bid/106128 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-18324
https://notcve.org/view.php?id=CVE-2017-18324
03 Jan 2019 — Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, SD 855, SDX24, Snapdragon_High_Med_2016. Material de clave criptográfica filtrado en los mensajes de depuración de GERAN en snapdragon mobile y snapdragon wear en sus version... • http://www.securityfocus.com/bid/106128 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •