CWE-823
98 CVEs • Abstraction: Base
Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
CVEs (98)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 4Sdm429w Firmware Snapdragon 429 Mobile Platform FirmwareWcn3620 Firmware+1 moreJun 17, 2026 Jun 3, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Memory corruption while handling test pattern generator IOCTL command. |
A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory. |
1Qualcomm 57C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+54 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occur during IO configuration processing when the IO port count is invalid. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
1Qualcomm 60Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+57 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation. |
1Qualcomm 41Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+38 moreJun 17, 2026 Mar 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
1Qualcomm 10Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcc2073 Firmware+7 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. |
1Qualcomm 24Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+21 moreJun 17, 2026 Feb 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption may occour while generating test pattern due to negative indexing of display ID. |
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory. |
1Qualcomm 34Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQam8295p Firmware+31 moreJun 17, 2026 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |