Loading HuntDB...

CVE-2023-28537

HIGH
Published 2023-08-08T09:15:01.370Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2023-28537. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
8.4
/10
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.001
probability
of exploitation in the wild

There is a 0.1% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.168
Higher than 16.8% of all CVEs

Attack Vector Metrics

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

Memory corruption while allocating memory in COmxApeDec module in Audio.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

Affected Versions:

315 5G IoT Modem APQ8017 AQT1000 AR8031 AR8035 CSRA6620 CSRA6640 CSRB31024 FastConnect 6200 FastConnect 6700 FastConnect 6800 FastConnect 6900 Flight RB5 5G Platform Home Hub 100 Platform MDM9628 MSM8108 MSM8208 MSM8209 MSM8608 MSM8917 MSM8996AU QAM8295P QCA6174A QCA6310 QCA6320 QCA6335 QCA6391 QCA6420 QCA6421 QCA6426 QCA6430 QCA6431 QCA6436 QCA6564 QCA6564A QCA6564AU QCA6574 QCA6574A QCA6574AU QCA6584AU QCA6595 QCA6595AU QCA6696 QCA6698AQ QCA8081 QCA8337 QCA9377 QCA9379 QCM2290 QCM4290 QCM6125 QCM6490 QCN9011 QCN9012 QCN9074 QCS2290 QCS410 QCS4290 QCS610 QCS6125 QCS6490 QRB5165M QRB5165N QSM8250 Qualcomm Robotics RB3 Platform Qualcomm Robotics RB5 Platform Qualcomm215 SA4150P SA4155P SA6145P SA6150P SA6155 SA6155P SA8145P SA8150P SA8155 SA8155P SA8195P SA8295P SD 636 SD 675 SD 8 Gen1 5G SD205 SD210 SD429 SD439 SD450 SD460 SD480 SD625 SD626 SD632 SD660 SD662 SD665 SD670 SD675 SD678 SD680 SD690 5G SD695 SD710 SD720G SD730 SD750G SD765 SD765G SD768G SD778G SD780G SD835 SD845 SD855 SD865 5G SD870 SD888 SDM429W SDM630 SDX55 SM4125 SM6250 SM6250P SM7250P SM7315 SM7325P Smart Audio 100 Platform Smart Audio 200 Platform Smart Display 200 Platform (APQ5053-AA) Snapdragon 820 Automotive Platform Snapdragon 835 Mobile PC Platform Snapdragon 888 5G Mobile Platform Snapdragon 888+ 5G Mobile Platform (SM8350-AC) Snapdragon Auto 5G Modem-RF Snapdragon Wear 4100+ Platform Snapdragon X12 LTE Modem Snapdragon X24 LTE Modem Snapdragon X50 5G Modem-RF System Snapdragon X55 5G Modem-RF System Snapdragon X65 5G Modem-RF System Snapdragon XR1 Platform Snapdragon XR2 5G Platform Snapdragon XR2+ Gen 1 Platform Snapdragon Auto 4G Modem Snapdragon 4 Gen 1 SXR1120 SXR2130 Vision Intelligence 100 Platform (APQ8053-AA) Vision Intelligence 200 Platform (APQ8053-AC) Vision Intelligence 400 Platform WCD9326 WCD9335 WCD9340 WCD9341 WCD9360 WCD9370 WCD9371 WCD9375 WCD9380 WCD9385 WCN3610 WCN3615 WCN3620 WCN3660 WCN3660B WCN3680 WCN3680B WCN3910 WCN3950 WCN3980 WCN3988 WCN3990 WCN3999 WCN6740 WSA8810 WSA8815 WSA8830 WSA8835

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed HIGH

GHSA-hwh2-grqv-74jx

Advisory Details

Memory corruption while allocating memory in COmxApeDec module in Audio.

CVSS Scoring

CVSS Score

7.5

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: August 8, 2023, Modified: April 4, 2024

References

Published: 2023-08-08T09:15:01.370Z
Last Modified: 2024-08-02T13:43:22.614Z
Copied to clipboard!