CVE-2022-25657 Vulnerability Details
/
/
/
CVE-2022-25657 Metadata Quick Info
CVE Published: 02/09/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: qualcomm |
Vendor: Qualcomm, Inc. |
Product: Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Status : PUBLISHED
CVE-2022-25657 Description
Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Metrics
CVSS Version: 3.1 |
Base Score: 7.3 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* LOW
Integrity Impact (I)* LOW
Availability Impact (A)* LOW
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: Buffer Copy Without Checking Size of Input in Video
Source: Qualcomm, Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).