CVE-2017-11076
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.21%
- CWE
- CWE-823
- Published
- 2024-11-26
- Last modified
- 2026-03-14
Affected products
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
Weakness type
Related vulnerabilities
- CVE-2023-33106 — Use of Out-of-range Pointer Offset in Graphics
- CVE-2023-43553 — Use of Out-of-range Pointer Offset in WLAN HOST
- CVE-2023-24855 — Use of Out-of-range Pointer Offset in Modem
- CVE-2023-22388 — Use of Out-of-range Pointer Offset in Multi-mode Call Processor
- CVE-2026-21732 — GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation
- CVE-2025-27059 — Use of Out-of-range Pointer Offset in TZ Firmware
- CVE-2020-6112 — An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.
- CVE-2023-46724 — SQUID-2023:4 Denial of Service in SSL Certificate validation