7.8
CVE-2023-21639
- EPSS 0.03%
- Veröffentlicht 04.07.2023 05:15:10
- Zuletzt bearbeitet 21.11.2024 07:43:16
- Quelle product-security@qualcomm.com
- Teams Watchlist Login
- Unerledigt Login
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Aqt1000 Firmware Version-
Qualcomm ≫ Fastconnect 6200 Firmware Version-
Qualcomm ≫ Qca6420 Firmware Version-
Qualcomm ≫ Qca6430 Firmware Version-
Qualcomm ≫ Sa4150p Firmware Version-
Qualcomm ≫ Sa4155p Firmware Version-
Qualcomm ≫ Sa6155p Firmware Version-
Qualcomm ≫ Sa8155p Firmware Version-
Qualcomm ≫ Sa8195p Firmware Version-
Qualcomm ≫ Sd855 Firmware Version-
Qualcomm ≫ Snapdragon 855 Firmware Version-
Qualcomm ≫ Snapdragon 855+/860 Firmware Version-
Qualcomm ≫ Snapdragon W5+ Gen 1 Firmware Version-
Qualcomm ≫ Sw5100 Firmware Version-
Qualcomm ≫ Sw5100p Firmware Version-
Qualcomm ≫ Wcd9341 Firmware Version-
Qualcomm ≫ Wcn3980 Firmware Version-
Qualcomm ≫ Wcn3988 Firmware Version-
Qualcomm ≫ Wsa8810 Firmware Version-
Qualcomm ≫ Wsa8815 Firmware Version-
Qualcomm ≫ Wsa8830 Firmware Version-
Qualcomm ≫ Wsa8835 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.05 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
product-security@qualcomm.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.