
CVE-2017-18296
https://notcve.org/view.php?id=CVE-2017-18296
23 Oct 2018 — Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDA660, SDX20. No se aplica el control de acceso en las aplicaciones al acceder a los servicios SafeSwitch, lo que puede conducir a un acceso incorrecto en Sn... • http://www.securitytracker.com/id/1041432 •

CVE-2017-18170
https://notcve.org/view.php?id=CVE-2017-18170
23 Oct 2018 — Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, SDM630, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016. Validación de entradas incorrecta en la función Bluetooth Controller puede conducir a una posible corrupción de memoria en Snapdragon Mobile en versiones QCA9379, SD 210/SD ... • https://source.android.com/security/bulletin/2018-07-01#qualcomm-closed-source-components • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVE-2017-18304
https://notcve.org/view.php?id=CVE-2017-18304
23 Oct 2018 — Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version FSM9055, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660 and SDX20 Asignación de memoria insuficiente en boot debido a que se pasa el tamaño incorrecto podría resultar en... • http://www.securitytracker.com/id/1041432 • CWE-125: Out-of-bounds Read •

CVE-2017-18294
https://notcve.org/view.php?id=CVE-2017-18294
23 Oct 2018 — While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size of ELF64 header size in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDA660, SDX20. Al leer el tipo de clase de archivo de la cabecera ELF, podría ocurrir un desbordamiento de búfe... • http://www.securitytracker.com/id/1041432 • CWE-125: Out-of-bounds Read •

CVE-2017-18299
https://notcve.org/view.php?id=CVE-2017-18299
23 Oct 2018 — Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660 La lógica de consolidación de tablas de traducción conduce al agotamiento de recursos y un error QSEE en Snapdragon Automobile, Snapdragon Mobile y Snapdragon Wear en versiones MDM9206, MDM9607, ... • http://www.securitytracker.com/id/1041432 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-18303
https://notcve.org/view.php?id=CVE-2017-18303
23 Oct 2018 — While processing the sensors registry configuration file, if inputs are not validated a buffer overflow will occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MMDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SDA660, SDX20. Al procesar el archivo de configuración de registro del sensor, si las entradas no se validan, ocurrirá un desbordamiento... • http://www.securitytracker.com/id/1041432 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-18277
https://notcve.org/view.php?id=CVE-2017-18277
23 Oct 2018 — When dynamic memory allocation fails, currently the process sleeps for one second and continues with infinite loop without retrying for memory allocation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCN5502, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835. Cuando la asignación de memoria dinámica fracasa, actualmente el proceso duerme durante un segundo y contin... • https://source.android.com/security/bulletin/2018-07-01#qualcomm-closed-source-components • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2017-18171
https://notcve.org/view.php?id=CVE-2017-18171
23 Oct 2018 — Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, SDM630, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016. Validación de entradas incorrecta para los paquetes de datos GATT en la función Bluetooth Controller puede conducir a una posible corrupción de... • https://source.android.com/security/bulletin/2018-07-01#qualcomm-closed-source-components • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-18155
https://notcve.org/view.php?id=CVE-2017-18155
12 Jul 2018 — While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault. Al reproducir contenido HEVC mediante HD DMB en Snapdragon Automobile y Snapdragon Mobile en las versiones MSM8996AU, SD 450, SD 625, SD 820, SD 820A y SD 835, puede emplearse una variable no inicializada, lo que conduce a un fallo del kernel. • https://source.android.com/security/bulletin/2018-06-01#qualcomm-components • CWE-20: Improper Input Validation •

CVE-2018-5891
https://notcve.org/view.php?id=CVE-2018-5891
06 Jul 2018 — While processing modem SSR after IMS is registered, the IMS data daemon is restarted but the ipc_dataHandle is no longer available. Consequently, the DPL thread frees the internal memory for dataDHandle but the local variable pointer is not updated which can lead to a Use After Free condition in Snapdragon Mobile and Snapdragon Wear. Al procesar el SSR del módem tras registrar IMS, el demonio de datos IMS se reinicia, pero el ipc_dataHandl ya no está disponible. En consecuencia, el hilo DPL libera la memori... • https://www.qualcomm.com/company/product-security/bulletins • CWE-416: Use After Free •