CVE-2018-11882
published 2018-10-29CVE-2018-11882: Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
PriorityP433high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| qualcomm_inc | snapdragon_mobile | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w652-7vhj-7967: Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
ghsa_unreviewed·2022-05-14
CVE-2018-11882 [HIGH] CWE-119 GHSA-w652-7vhj-7967: Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Android
CVE-2018-11882: Closed-source component
vendor_android·2019-04-01·CVSS 7.8
CVE-2018-11882 [HIGH] CVE-2018-11882: Closed-source component
Android Security Bulletin 2019-04-01
CVE: CVE-2018-11882
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-111093259*
No detection rules found.
No public exploits indexed.
Checkpoint
17th June – Threat Intelligence Bulletin
blogs_checkpoint·2019-06-17·CVSS 7.8
CVE-2017-11882 [HIGH] 17th June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 10th June 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
Belgium-based airplane parts and aviation structuring business ASCO Industries has shuttered its plants in Belgium, Germany, Canada and the US after falling victim to a ransomware attack. Nearly 1,000 employees were sent home for the entire week.
Telegram’s founder Pavel Durov links China with the powerful DDoS attack, wh
Trendmicro
Attack Using Windows Installer Leads to LokiBot
blogs_trendmicro·2018-02-08·CVSS 7.8
CVE-2017-11882 [HIGH] Attack Using Windows Installer Leads to LokiBot
Ciberamenazas
## Attack Using Windows Installer Leads to LokiBot
Recently, we discovered CVE-2017-11882 being exploited again in an attack that uses an uncommon method of installation—via the Windows Installer service in Microsoft Windows operating systems.
By: Martin Co, Gilbert Sison Feb 08, 2018 Read time: ( words)
Save to Folio
Back in November 2017, Microsoft patched CVE-2017-11882 , a remote code execution vulnerability that affected Microsoft Office. However, this didn’t prevent cybercrime groups such as Cobalt from exploiting this vulnerability in order to deliver a variety of malware , including FAREIT , Ursnif , and a cracked version of the Loki infostealer , a keylogger that was primarily advertised as capable of stealing passwords and cryptocurrency wallets.
Recently, we
2018-10-29
Published