6.7

CVE-2024-23378

Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.

Data is provided by the National Vulnerability Database (NVD)
QualcommSrv1m Firmware Version-
   QualcommSrv1m Version-
QualcommSrv1h Firmware Version-
   QualcommSrv1h Version-
QualcommSa9000p Firmware Version-
   QualcommSa9000p Version-
QualcommSa8775p Firmware Version-
   QualcommSa8775p Version-
QualcommSa8770p Firmware Version-
   QualcommSa8770p Version-
QualcommSa8650p Firmware Version-
   QualcommSa8650p Version-
QualcommSa8620p Firmware Version-
   QualcommSa8620p Version-
QualcommSa8255p Firmware Version-
   QualcommSa8255p Version-
QualcommSa7775p Firmware Version-
   QualcommSa7775p Version-
QualcommSa7255p Firmware Version-
   QualcommSa7255p Version-
QualcommQca6698aq Firmware Version-
   QualcommQca6698aq Version-
QualcommQca6584au Firmware Version-
   QualcommQca6584au Version-
QualcommQamsrv1m Firmware Version-
   QualcommQamsrv1m Version-
QualcommQamsrv1h Firmware Version-
   QualcommQamsrv1h Version-
QualcommQam8775p Firmware Version-
   QualcommQam8775p Version-
QualcommQam8650p Firmware Version-
   QualcommQam8650p Version-
QualcommQam8255p Firmware Version-
   QualcommQam8255p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.064
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.