7.8

CVE-2024-45577

Improper Input Validation in Camera Driver

Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Fastconnect 6900 Firmware Version -
   Qualcomm ≫ Fastconnect 6900 Version -
Qualcomm ≫ Fastconnect 7800 Firmware Version -
   Qualcomm ≫ Fastconnect 7800 Version -
Qualcomm ≫ Sdm429w Firmware Version -
   Qualcomm ≫ Sdm429w Version -
Qualcomm ≫ Wcd9380 Firmware Version -
   Qualcomm ≫ Wcd9380 Version -
Qualcomm ≫ Wcn3620 Firmware Version -
   Qualcomm ≫ Wcn3620 Version -
Qualcomm ≫ Wcn3660b Firmware Version -
   Qualcomm ≫ Wcn3660b Version -
Qualcomm ≫ Wsa8830 Firmware Version -
   Qualcomm ≫ Wsa8830 Version -
Qualcomm ≫ Wsa8835 Firmware Version -
   Qualcomm ≫ Wsa8835 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.014
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Qualcomm 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2025-bulletin.html
Patch
Vendor Advisory