8.4

CVE-2023-21630

Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.

Data is provided by the National Vulnerability Database (NVD)
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6574 Firmware Version-
   QualcommQca6574 Version-
QualcommQca6574a Firmware Version-
   QualcommQca6574a Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6595au Firmware Version-
   QualcommQca6595au Version-
QualcommQca6696 Firmware Version-
   QualcommQca6696 Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSa8195p Firmware Version-
   QualcommSa8195p Version-
QualcommSd680 Firmware Version-
   QualcommSd680 Version-
QualcommSd778g Firmware Version-
   QualcommSd778g Version-
QualcommSd888 Firmware Version-
   QualcommSd888 Version-
QualcommSg4150p Firmware Version-
   QualcommSg4150p Version-
QualcommSm6225-ad Firmware Version-
   QualcommSm6225-ad Version-
QualcommSm7315 Firmware Version-
   QualcommSm7315 Version-
QualcommSm7325 Firmware Version-
   QualcommSm7325 Version-
QualcommSm7325-ae Firmware Version-
   QualcommSm7325-ae Version-
QualcommSm7325-af Firmware Version-
   QualcommSm7325-af Version-
QualcommSm7325p Firmware Version-
   QualcommSm7325p Version-
QualcommSm7350-ab Firmware Version-
   QualcommSm7350-ab Version-
QualcommSm8350 Firmware Version-
   QualcommSm8350 Version-
QualcommSm8350-ac Firmware Version-
   QualcommSm8350-ac Version-
QualcommSm8450 Firmware Version-
   QualcommSm8450 Version-
QualcommSm8475 Firmware Version-
   QualcommSm8475 Version-
QualcommSw5100 Firmware Version-
   QualcommSw5100 Version-
QualcommSw5100p Firmware Version-
   QualcommSw5100p Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn6740 Firmware Version-
   QualcommWcn6740 Version-
QualcommWcn6750 Firmware Version-
   QualcommWcn6750 Version-
QualcommWcn685x-1 Firmware Version-
   QualcommWcn685x-1 Version-
QualcommWcn685x-5 Firmware Version-
   QualcommWcn685x-5 Version-
QualcommWcn785x-1 Firmware Version-
   QualcommWcn785x-1 Version-
QualcommWcn785x-5 Firmware Version-
   QualcommWcn785x-5 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.158
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CWE-191 Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.