CVE-2021-22156 Vulnerability Details

  /     /     /  

CVE-2021-22156 Metadata Quick Info

CVE Published: 17/08/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: blackberry | Vendor: n/a | Product: BlackBerry QNX Software Development Platform (SDP), QNX OS for Medical and QNX OS for Safety
Status : PUBLISHED

CVE-2021-22156 Description

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Denial of service or arbitrary code execution
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).