CVE-2021-35074

HIGH

Snapdragon Auto-Snapdragon Mobile - Buffer Overflow

Title source: llm
STIX 2.1

Description

Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (41)
qualcomm/ar8035_firmware
qualcomm/qca6174a_firmware
qualcomm/qca6391_firmware
qualcomm/qca6574au_firmware
qualcomm/qca6595au_firmware
qualcomm/qca6696_firmware
qualcomm/qca8081_firmware
qualcomm/qca8337_firmware
qualcomm/qca9377_firmware
qualcomm/qcm6490_firmware
... and 31 more
Published Feb 11, 2022
Tracked Since Feb 18, 2026