8.4

CVE-2021-35115

Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommApq8096au Firmware Version-
   QualcommApq8096au Version-
QualcommAr6003 Firmware Version-
   QualcommAr6003 Version-
QualcommMdm8215 Firmware Version-
   QualcommMdm8215 Version-
QualcommMdm8215m Firmware Version-
   QualcommMdm8215m Version-
QualcommMdm8615m Firmware Version-
   QualcommMdm8615m Version-
QualcommMdm9215 Firmware Version-
   QualcommMdm9215 Version-
QualcommMdm9310 Firmware Version-
   QualcommMdm9310 Version-
QualcommMdm9615 Firmware Version-
   QualcommMdm9615 Version-
QualcommMdm9615m Firmware Version-
   QualcommMdm9615m Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQca6564a Firmware Version-
   QualcommQca6564a Version-
QualcommQca6564au Firmware Version-
   QualcommQca6564au Version-
QualcommQca6574a Firmware Version-
   QualcommQca6574a Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6584au Firmware Version-
   QualcommQca6584au Version-
QualcommQca6696 Firmware Version-
   QualcommQca6696 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6150p Firmware Version-
   QualcommSa6150p Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8145p Firmware Version-
   QualcommSa8145p Version-
QualcommSa8150p Firmware Version-
   QualcommSa8150p Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSa8195p Firmware Version-
   QualcommSa8195p Version-
QualcommSa8540p Firmware Version-
   QualcommSa8540p Version-
QualcommSa9000p Firmware Version-
   QualcommSa9000p Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.131
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
product-security@qualcomm.com 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.