Auto-Update: 2023-05-02T08:00:28.719397+00:00

This commit is contained in:
René Helmke 2023-05-02 10:00:31 +02:00
parent c7b8e2c5af
commit 884dd376a1
12 changed files with 489 additions and 9 deletions

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-25713",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:08.500",
"lastModified": "2023-05-02T06:15:08.500",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-33281",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:09.507",
"lastModified": "2023-05-02T06:15:09.507",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-33292",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:09.757",
"lastModified": "2023-05-02T06:15:09.757",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-33304",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:09.910",
"lastModified": "2023-05-02T06:15:09.910",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-33305",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:09.997",
"lastModified": "2023-05-02T06:15:09.997",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-34144",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.077",
"lastModified": "2023-05-02T06:15:10.077",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Transient DOS due to reachable assertion in Modem during OSI decode scheduling."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-40505",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.173",
"lastModified": "2023-05-02T06:15:10.173",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Information disclosure due to buffer over-read in Modem while parsing DNS hostname."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "LOW",
"baseScore": 8.2,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 4.2
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2022-40508",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.263",
"lastModified": "2023-05-02T06:15:10.263",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2023-21642",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.347",
"lastModified": "2023-05-02T06:15:10.347",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory corruption in HAB Memory management due to broad system privileges via physical address."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.5,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2023-21665",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.433",
"lastModified": "2023-05-02T06:15:10.433",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory corruption in Graphics while importing a file."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.5,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -0,0 +1,43 @@
{
"id": "CVE-2023-21666",
"sourceIdentifier": "product-security@qualcomm.com",
"published": "2023-05-02T06:15:10.510",
"lastModified": "2023-05-02T06:15:10.510",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "product-security@qualcomm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.5,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin",
"source": "product-security@qualcomm.com"
}
]
}

View File

@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2023-05-02T06:00:23.783014+00:00
2023-05-02T08:00:28.719397+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2023-05-02T05:15:28.113000+00:00
2023-05-02T06:15:10.510000+00:00
```
### Last Data Feed Release
@ -29,23 +29,30 @@ Download and Changelog: [Click](releases/latest)
### Total Number of included CVEs
```plain
213881
213892
```
### CVEs added in the last Commit
Recently added CVEs: `3`
Recently added CVEs: `11`
* [CVE-2022-48482](CVE-2022/CVE-2022-484xx/CVE-2022-48482.json) (`2023-05-02T05:15:27.407`)
* [CVE-2022-48483](CVE-2022/CVE-2022-484xx/CVE-2022-48483.json) (`2023-05-02T05:15:28.057`)
* [CVE-2023-2247](CVE-2023/CVE-2023-22xx/CVE-2023-2247.json) (`2023-05-02T05:15:28.113`)
* [CVE-2022-25713](CVE-2022/CVE-2022-257xx/CVE-2022-25713.json) (`2023-05-02T06:15:08.500`)
* [CVE-2022-33281](CVE-2022/CVE-2022-332xx/CVE-2022-33281.json) (`2023-05-02T06:15:09.507`)
* [CVE-2022-33292](CVE-2022/CVE-2022-332xx/CVE-2022-33292.json) (`2023-05-02T06:15:09.757`)
* [CVE-2022-33304](CVE-2022/CVE-2022-333xx/CVE-2022-33304.json) (`2023-05-02T06:15:09.910`)
* [CVE-2022-33305](CVE-2022/CVE-2022-333xx/CVE-2022-33305.json) (`2023-05-02T06:15:09.997`)
* [CVE-2022-34144](CVE-2022/CVE-2022-341xx/CVE-2022-34144.json) (`2023-05-02T06:15:10.077`)
* [CVE-2022-40505](CVE-2022/CVE-2022-405xx/CVE-2022-40505.json) (`2023-05-02T06:15:10.173`)
* [CVE-2022-40508](CVE-2022/CVE-2022-405xx/CVE-2022-40508.json) (`2023-05-02T06:15:10.263`)
* [CVE-2023-21642](CVE-2023/CVE-2023-216xx/CVE-2023-21642.json) (`2023-05-02T06:15:10.347`)
* [CVE-2023-21665](CVE-2023/CVE-2023-216xx/CVE-2023-21665.json) (`2023-05-02T06:15:10.433`)
* [CVE-2023-21666](CVE-2023/CVE-2023-216xx/CVE-2023-21666.json) (`2023-05-02T06:15:10.510`)
### CVEs modified in the last Commit
Recently modified CVEs: `1`
Recently modified CVEs: `0`
* [CVE-2022-28005](CVE-2022/CVE-2022-280xx/CVE-2022-28005.json) (`2023-05-02T04:15:46.873`)
## Download and Usage