← Vulnerability feed

Vulnerability record · CVE-2017-18173 · published 6 May 2019

CVE-2017-18173: Qualcomm sd 425 firmware integer overflow vulnerability

Qualcomm · Sd 425 Firmware

In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016.

7.8 CVSS 3.0 High EPSS 0.23% · top 87.7% CWE-190 · Integer overflow
7.8CVSS 3.0 base score, v2 7.2
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18173 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11076Qualcomm msm8909w firmware memory buffer overflow vulnerabilityOn some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can…EPSS 0.35%9.8CVE-2017-17772Qualcomm sd 450 firmware out-of-bounds read vulnerabilityIn multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.EPSS 0.35%9.8CVE-2019-2258Qualcomm mdm9150 firmware out-of-bounds write vulnerabilityImproper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…EPSS 0.91%9.8CVE-2019-2323Qualcomm mdm9150 firmware vulnerabilityLack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, Snapdragon C…EPSS 0.91%9.8CVE-2019-2332Qualcomm mdm9150 firmware out-of-bounds write vulnerabilityMemory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum…EPSS 0.91%9.8CVE-2019-2324Qualcomm mdm9150 firmware memory buffer overflow vulnerabilityWhen ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapd…EPSS 0.91%9.8CVE-2019-2249Qualcomm ipq8074 firmware out-of-bounds read vulnerabilityKernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…EPSS 1.4%9.8CVE-2019-2285Qualcomm msm8909w firmware out-of-bounds write vulnerabilityOut of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon Auto, Snapdr…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2017-18173), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.