← Vulnerability feed

Vulnerability record · CVE-2017-18307 · published 26 November 2024

CVE-2017-18307: Qualcomm sd 450 firmware information exposure vulnerability

Qualcomm · Sd 450 Firmware

Information disclosure possible while audio playback.

5.5 CVSS 3.1 Medium EPSS 0.11% · top 98.6% CWE-200 · Information exposure
5.5CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Information disclosure possible while audio playback.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18307 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11076Qualcomm msm8909w firmware memory buffer overflow vulnerabilityOn some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can…EPSS 0.35%9.8CVE-2017-17772Qualcomm sd 450 firmware out-of-bounds read vulnerabilityIn multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.EPSS 0.35%9.8CVE-2019-2283Qualcomm mdm9150 firmware out-of-bounds read vulnerabilityImproper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdr…EPSS 0.91%9.8CVE-2019-2258Qualcomm mdm9150 firmware out-of-bounds write vulnerabilityImproper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…EPSS 0.91%9.8CVE-2019-2324Qualcomm mdm9150 firmware memory buffer overflow vulnerabilityWhen ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapd…EPSS 0.91%9.8CVE-2019-2325Qualcomm mdm9150 firmware vulnerabilityOut of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compu…EPSS 0.91%9.8CVE-2019-2331Qualcomm mdm9150 firmware integer overflow vulnerabilityPossible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Com…EPSS 1.2%9.8CVE-2019-2249Qualcomm ipq8074 firmware out-of-bounds read vulnerabilityKernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2017-18307), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.