5.5

CVE-2023-48346

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 11.0
   Unisoc ≫ S8000 Version -
   Unisoc ≫ Sc7731e Version -
   Unisoc ≫ Sc9832e Version -
   Unisoc ≫ Sc9863a Version -
   Unisoc ≫ T310 Version -
   Unisoc ≫ T606 Version -
   Unisoc ≫ T610 Version -
   Unisoc ≫ T612 Version -
   Unisoc ≫ T616 Version -
   Unisoc ≫ T618 Version -
   Unisoc ≫ T760 Version -
   Unisoc ≫ T770 Version -
   Unisoc ≫ T820 Version -
Google ≫ Android Version 12.0
   Unisoc ≫ S8000 Version -
   Unisoc ≫ Sc7731e Version -
   Unisoc ≫ Sc9832e Version -
   Unisoc ≫ Sc9863a Version -
   Unisoc ≫ T310 Version -
   Unisoc ≫ T606 Version -
   Unisoc ≫ T610 Version -
   Unisoc ≫ T612 Version -
   Unisoc ≫ T616 Version -
   Unisoc ≫ T618 Version -
   Unisoc ≫ T760 Version -
   Unisoc ≫ T770 Version -
   Unisoc ≫ T820 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.003
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.unisoc.com/en_us/secy/announcementDetail/1745735200442220545
Vendor Advisory