Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge i…
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9655, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
https://cwe.mitre.org/data/definitions/330.html →Open in CWE collection →This attack targets predictable session ID in order to gain privileges. The attacker can predict the session ID used during a transaction to perform spoofing and session hijacking.
https://capec.mitre.org/data/definitions/59.html →Open in CAPEC collection →In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to this asset by using trial-and-error to exhaustively explore all the possible secret values in the hope of finding the secret (or a value that is functionally equivalent) that will unlock the asset.
https://capec.mitre.org/data/definitions/112.html →Open in CAPEC collection →An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
https://capec.mitre.org/data/definitions/485.html →Open in CAPEC collection →| Product | Vendor | Status |
|---|---|---|
| mdm9205_firmware | * | Tracked |
| mdm9206_firmware | * | Tracked |
| mdm9607_firmware | * | Tracked |
| mdm9615_firmware | * | Tracked |
| mdm9625_firmware | * | Tracked |
| mdm9635m_firmware | * | Tracked |
| mdm9655_firmware | * | Tracked |
| msm8909w_firmware | * | Tracked |
| msm8996au_firmware | * | Tracked |
| qcs605_firmware | * | Tracked |
| qualcomm_215_firmware | * | Tracked |
| sd_205_firmware | * | Tracked |
| sd_210_firmware | * | Tracked |
| sd_212_firmware | * | Tracked |
| sd_410_firmware | * | Tracked |
| sd_412_firmware | * | Tracked |
| sd_425_firmware | * | Tracked |
| sd_427_firmware | * | Tracked |
| sd_429_firmware | * | Tracked |
| sd_430_firmware | * | Tracked |