Security News

CVE-2018-17619

National Vulnerability Database - Mon, 10/29/2018 - 17:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Validate events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6352.
Categories: Security News

CVE-2018-17620

National Vulnerability Database - Mon, 10/29/2018 - 17:29
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6353.
Categories: Security News

CVE-2018-18387

National Vulnerability Database - Mon, 10/29/2018 - 14:29
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
Categories: Security News

CVE-2018-17908

National Vulnerability Database - Mon, 10/29/2018 - 14:29
WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.
Categories: Security News

CVE-2018-17910

National Vulnerability Database - Mon, 10/29/2018 - 14:29
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
Categories: Security News

CVE-2018-11880

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Categories: Security News

CVE-2018-11882

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Categories: Security News

CVE-2018-11884

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
Categories: Security News

CVE-2018-11877

National Vulnerability Database - Mon, 10/29/2018 - 14:29
When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Categories: Security News

CVE-2018-11879

National Vulnerability Database - Mon, 10/29/2018 - 14:29
When the buffer length passed is very large, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 845
Categories: Security News

CVE-2018-11875

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.
Categories: Security News

CVE-2018-11876

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Categories: Security News

CVE-2018-11872

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660
Categories: Security News

CVE-2018-11873

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mobile in version SD 845.
Categories: Security News

CVE-2018-11874

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
Categories: Security News

CVE-2018-11870

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number of legacy rates in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20.
Categories: Security News

CVE-2018-11871

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Buffer overwrite can happen in WLAN function while processing set pdev paramter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016.
Categories: Security News

CVE-2018-11866

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Integer overflow may happen in WLAN when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016.
Categories: Security News

CVE-2018-11867

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.
Categories: Security News

CVE-2018-11857

National Vulnerability Database - Mon, 10/29/2018 - 14:29
Improper input validation in WLAN encrypt/decrypt module can lead to a buffer copy in Snapdragon Mobile in version SD 835, SD 845, SD 850
Categories: Security News

Pages