2019-07-25 19:15:13 2019-08-05 19:19:08

improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

Vector

LOCAL

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

NONE

Availability

COMPLETE
Qualcomm Ipq4019 firmware - (not an official CPE) Qualcomm Ipq8064 firmware - (not an official CPE) Qualcomm Ipq8074 firmware - (not an official CPE) Qualcomm Mdm9150 firmware - (not an official CPE) Qualcomm Mdm9640 firmware - (not an official CPE) Qualcomm Mdm9650 firmware - (not an official CPE) Qualcomm Msm8909w firmware - (not an official CPE) Qualcomm Msm8996au firmware - (not an official CPE) Qualcomm Qcs405 firmware - (not an official CPE) Qualcomm Qcs605 firmware - (not an official CPE) Qualcomm Qualcomm 215 firmware - (not an official CPE) Qualcomm Sd 425 firmware - (not an official CPE) Qualcomm Sd 427 firmware - (not an official CPE) Qualcomm Sd 429 firmware - (not an official CPE) Qualcomm Sd 430 firmware - (not an official CPE) Qualcomm Sd 435 firmware - (not an official CPE) Qualcomm Sd 439 firmware - (not an official CPE) Qualcomm Sd 450 firmware - (not an official CPE) Qualcomm Sd 625 firmware - (not an official CPE) Qualcomm Sd 632 firmware - (not an official CPE) Qualcomm Sd 636 firmware - (not an official CPE) Qualcomm Sd 665 firmware - (not an official CPE) Qualcomm Sd 670 firmware - (not an official CPE) Qualcomm Sd 675 firmware - (not an official CPE) Qualcomm Sd 710 firmware - (not an official CPE) Qualcomm Sd 712 firmware - (not an official CPE) Qualcomm Sd 730 firmware - (not an official CPE) Qualcomm Sd 820a firmware - (not an official CPE) Qualcomm Sd 835 firmware - (not an official CPE) Qualcomm Sd 845 firmware - (not an official CPE) Qualcomm Sd 850 firmware - (not an official CPE) Qualcomm Sd 855 firmware - (not an official CPE) Qualcomm Sda660 firmware - (not an official CPE) Qualcomm Sdm439 firmware - (not an official CPE) Qualcomm Sdm630 firmware - (not an official CPE) Qualcomm Sdm660 firmware - (not an official CPE) Qualcomm Sdx20 firmware - (not an official CPE) Qualcomm Sdx24 firmware - (not an official CPE)

Improper Input Validation (ID 20)

Related CAPEC 58 Buffer Overflow via Environment Variables (CAPEC-ID 10) Server Side Include (SSI) Injection (CAPEC-ID 101) Cross Zone Scripting (CAPEC-ID 104) Cross Site Scripting through Log Files (CAPEC-ID 106) Command Line Execution through SQL Injection (CAPEC-ID 108) Object Relational Mapping Injection (CAPEC-ID 109) SQL Injection through SOAP Parameter Tampering (CAPEC-ID 110) Subverting Environment Variable Values (CAPEC-ID 13) Format String Injection (CAPEC-ID 135) LDAP Injection (CAPEC-ID 136) Relative Path Traversal (CAPEC-ID 139) Client-side Injection-induced Buffer Overflow (CAPEC-ID 14) Variable Manipulation (CAPEC-ID 171) Embedding Scripts in Non-Script Elements (CAPEC-ID 18) Flash Injection (CAPEC-ID 182) Cross-Site Scripting Using Alternate Syntax (CAPEC-ID 199) Exploiting Trust in Client (aka Make the Client Invisible) (CAPEC-ID 22) XML Nested Payloads (CAPEC-ID 230) XML Oversized Payloads (CAPEC-ID 231) Filter Failure through Buffer Overflow (CAPEC-ID 24) Cross-Site Scripting via Encoded URI Schemes (CAPEC-ID 244) XML Injection (CAPEC-ID 250) Environment Variable Manipulation (CAPEC-ID 264) Global variable manipulation (CAPEC-ID 265) Leverage Alternate Encoding (CAPEC-ID 267) Fuzzing (CAPEC-ID 28) Using Leading 'Ghost' Character Sequences to Bypass Input Filters (CAPEC-ID 3) Accessing/Intercepting/Modifying HTTP Cookies (CAPEC-ID 31) Embedding Scripts in HTTP Query Strings (CAPEC-ID 32) MIME Conversion (CAPEC-ID 42) Exploiting Multiple Input Interpretation Layers (CAPEC-ID 43) Buffer Overflow via Symbolic Links (CAPEC-ID 45) Overflow Variables and Tags (CAPEC-ID 46) Buffer Overflow via Parameter Expansion (CAPEC-ID 47) Signature Spoof (CAPEC-ID 473) XML Client-Side Attack (CAPEC-ID 484) Embedding NULL Bytes (CAPEC-ID 52) Postfix, Null Terminate, and Backslash (CAPEC-ID 53) Simple Script Injection (CAPEC-ID 63) Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64) SQL Injection (CAPEC-ID 66) String Format Overflow in syslog() (CAPEC-ID 67) Blind SQL Injection (CAPEC-ID 7) Using Unicode Encoding to Bypass Validation Logic (CAPEC-ID 71) URL Encoding (CAPEC-ID 72) User-Controlled Filename (CAPEC-ID 73) Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78) Using Slashes in Alternate Encoding (CAPEC-ID 79) Buffer Overflow in an API Call (CAPEC-ID 8) Using UTF-8 Encoding to Bypass Validation Logic (CAPEC-ID 80) Web Logs Tampering (CAPEC-ID 81) XPath Injection (CAPEC-ID 83) AJAX Fingerprinting (CAPEC-ID 85) Embedding Script (XSS) in HTTP Headers (CAPEC-ID 86) OS Command Injection (CAPEC-ID 88) Buffer Overflow in Local Command-Line Utilities (CAPEC-ID 9) XSS in IMG Tags (CAPEC-ID 91) XML Parser Attack (CAPEC-ID 99)