7.8
CVE-2025-21486
- EPSS 0.07%
- Veröffentlicht 03.06.2025 05:53:03
- Zuletzt bearbeitet 20.08.2025 20:25:35
- Quelle product-security@qualcomm.com
- CVE-Watchlists
- Unerledigt
Untrusted Pointer Dereference in DSP Service
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Fastconnect 6900 Firmware Version-
Qualcomm ≫ Fastconnect 7800 Firmware Version-
Qualcomm ≫ Qmp1000 Firmware Version-
Qualcomm ≫ Sm8735 Firmware Version-
Qualcomm ≫ Sm8750 Firmware Version-
Qualcomm ≫ Sm8750p Firmware Version-
Qualcomm ≫ Sw5100 Firmware Version-
Qualcomm ≫ Sw5100p Firmware Version-
Qualcomm ≫ Sxr2230p Firmware Version-
Qualcomm ≫ Sxr2250p Firmware Version-
Qualcomm ≫ Sxr2330p Firmware Version-
Qualcomm ≫ Wcd9378 Firmware Version-
Qualcomm ≫ Wcd9380 Firmware Version-
Qualcomm ≫ Wcd9385 Firmware Version-
Qualcomm ≫ Wcd9395 Firmware Version-
Qualcomm ≫ Wcn3660b Firmware Version-
Qualcomm ≫ Wcn3680b Firmware Version-
Qualcomm ≫ Wcn3980 Firmware Version-
Qualcomm ≫ Wcn3988 Firmware Version-
Qualcomm ≫ Wcn7750 Firmware Version-
Qualcomm ≫ Wcn7860 Firmware Version-
Qualcomm ≫ Wcn7861 Firmware Version-
Qualcomm ≫ Wcn7880 Firmware Version-
Qualcomm ≫ Wcn7881 Firmware Version-
Qualcomm ≫ Wsa8830 Firmware Version-
Qualcomm ≫ Wsa8832 Firmware Version-
Qualcomm ≫ Wsa8835 Firmware Version-
Qualcomm ≫ Wsa8840 Firmware Version-
Qualcomm ≫ Wsa8845 Firmware Version-
Qualcomm ≫ Wsa8845h Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| product-security@qualcomm.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.