AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-11955

CRITICAL · CVSS 9.8 EPSS 0.81%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-14 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-11955
Severity
CRITICAL
CVSS
9.8
EPSS
0.81%

Original Filing — NVD Description

Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame and results in out of bound read in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 665, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM660, SDX20, SDX24