Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8q7c-5gh4-x64v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.

In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.

EPSS

Процентиль: 18%
0.00059
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 8 лет назад

In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.

fstec
около 9 лет назад

Уязвимость функции аудио драйвера мобильного приложения MSM для операционной системы Android, позволяющая нарушителю вызвать переполнение буфера

EPSS

Процентиль: 18%
0.00059
Низкий

7.8 High

CVSS3