peter bassill · operator
$ cve CVE-2021-30351 JSON

CVE-2021-30351

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.02% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2022-01-03
Last modified2026-06-17

Affected (40)

VendorProduct
qualcommapq8009
qualcommapq8009 firmware
qualcommapq8009w
qualcommapq8009w firmware
qualcommapq8017
qualcommapq8017 firmware
qualcommaqt1000
qualcommaqt1000 firmware
qualcommar8031
qualcommar8031 firmware
qualcommar8035
qualcommar8035 firmware
qualcommar9380
qualcommar9380 firmware
qualcommcsr8811
qualcommcsr8811 firmware
qualcommcsra6620
qualcommcsra6620 firmware
qualcommcsra6640
qualcommcsra6640 firmware
qualcommcsrb31024
qualcommcsrb31024 firmware
qualcommfsm10055
qualcommfsm10055 firmware
qualcommfsm10056
qualcommfsm10056 firmware
qualcommipq4018
qualcommipq4018 firmware
qualcommipq4028
qualcommipq4028 firmware
qualcommipq4029
qualcommipq4029 firmware
qualcommipq6000
qualcommipq6000 firmware
qualcommipq6010
qualcommipq6010 firmware
qualcommipq6018
qualcommipq6018 firmware
qualcommipq6028
qualcommipq6028 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD