CVE-2018-5868
Last modified
CVE-2018-5868 is a vulnerability of currently unknown severity. Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 425, SD 430, SD 450, SD 625, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Msm8996au Firmware | All versions |
| Qualcomm | Sd 425 Firmware | All versions |
| Qualcomm | Sd 430 Firmware | All versions |
| Qualcomm | Sd 450 Firmware | All versions |
| Qualcomm | Sd 625 Firmware | All versions |
| Qualcomm | Sd 712 Firmware | All versions |
| Qualcomm | Sd 710 Firmware | All versions |
| Qualcomm | Sd 670 Firmware | All versions |
| Qualcomm | Sd 820 Firmware | All versions |
| Qualcomm | Sd 820a Firmware | All versions |
| Qualcomm | Sd 835 Firmware | All versions |
| Qualcomm | Sd 845 Firmware | All versions |
| Qualcomm | Sd 850 Firmware | All versions |
| Qualcomm | Sda660 Firmware | All versions |
| Qualcomm | Sdx24 Firmware | All versions |
| Qualcomm | Sxr1130 Firmware | All versions |
References
- http://www.securityfocus.com/bid/106128Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- http://www.securityfocus.com/bid/106128Third Party Advisory, VDB Entry
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5868?
How severe is CVE-2018-5868?
How do I fix CVE-2018-5868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5862In __wlan_hdd_cfg80211_vendor_scan() in all Android releases…
- CVE-2018-5863If userspace provides a too-large WPA RSN IE length in wlan_…
- CVE-2018-5864While processing a WMI_APFIND event in all Android releases …
- CVE-2018-5865While processing a debug log event from firmware in all Andr…
- CVE-2018-5866While processing logs, data is copied into a buffer pointed …
- CVE-2018-5867Lack of checking input size can lead to buffer overflow In W…
- CVE-2018-5869Improper input validation in the QTEE keymaster app can lead…
- CVE-2018-5870While loading a service image, an untrusted pointer derefere…
- CVE-2018-5871In Snapdragon (Automobile, Mobile, Wear) in version MDM9206,…
- CVE-2018-5872While parsing over-the-air information elements in all Andro…
- CVE-2018-5873An issue was discovered in the __ns_get_path function in fs/…7
- CVE-2018-5874While parsing an mp4 file, a stack-based buffer overflow can…
Are you affected by CVE-2018-5868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
