CVE detail
CVE-2023-24855
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- Qualcomm patches 3 actively exploited zero-daysHelp Net Security
Qualcomm has fixed three actively exploited vulnerabilities (CVE-2023-33106, CVE-2023-33107, CVE-2023-33063) in its Adreno GPU and Compute DSP drivers. Vulnerabilities exploited in Qualcomm GPU and DSP drivers The US-based semiconductor company has been notified by Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2023-33063, and CVE-2022-22071 “may be under limited, targeted exploitation”. CVE-2022-22071 is an older use-after-free vulnerability found in Automotive Android OS and patched in May 2022. Additional information about the three … More →
newswww.helpnetsecurity.comOct 4, 2023, 1:43 PM - Chipmaker Qualcomm warns of three actively exploited zero-daysSecurity Affairs
Chipmaker Qualcomm addressed 17 vulnerabilities in various components and warns of three other actively exploited zero-day flaws. Chipmaker Qualcomm released security updates to address 17 vulnerabilities in several components. Three out of 17 flaws are rated Critical, 13 are rated High, and one is rated Medium in severity. The company is also warning that three […]
newssecurityaffairs.comOct 4, 2023, 1:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-28582CVSS 9.8 · Critical
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
- CVE-2023-33100CVSS 7.5 · High
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
- CVE-2023-33103CVSS 7.5 · High
Transient DOS while processing CAG info IE received from NW.
- CVE-2023-33084CVSS 7.5 · High
Transient DOS while processing IE fragments from server during DTLS handshake.
- CVE-2023-33060CVSS 7.1 · High
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
- CVE-2023-33058CVSS 8.2 · High
Information disclosure in Modem while processing SIB5.