CVE-2018-11854
published 2018-10-26CVE-2018-11854: Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| qualcomm_inc | snapdragon_mobile | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2018-11854: Closed-source component
vendor_android·2019-04-01·CVSS 7.8
CVE-2018-11854 [HIGH] CVE-2018-11854: Closed-source component
Android Security Bulletin 2019-04-01
CVE: CVE-2018-11854
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-111093762*
GHSA
GHSA-9pjw-xhv9-q834: Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
ghsa_unreviewed·2022-05-14
CVE-2018-11854 [HIGH] CWE-119 GHSA-9pjw-xhv9-q834: Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
No detection rules found.
Nuclei
Micro Focus UCMDB - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-11854 [CRITICAL] Micro Focus UCMDB - Remote Code Execution
Micro Focus UCMDB - Remote Code Execution
Micro Focus UCMDB is susceptible to remote code execution. Impacted products include Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions, and Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.), and Application Performance Management versions 9,51, 9.50 and 9.40 with UCMDB 10.33 CUP 3.
Template:
id: CVE-2020-11854
info:
name: Micro Focus UCMDB - Remote Code Execution
author: dwisiswant0
severity: critical
description: |
Micro Focus UCMDB is susceptible to remote code execution. Impacted products include Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,
No writeups or analysis indexed.
2018-10-26
Published