CWE-823
104 CVEs • Abstraction: Base
Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
CVEs (104)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 130Ar8035 Firmware Csr8811 FirmwareFastconnect 6900 Firmware+127 moreJun 17, 2026 Mar 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE. |
1Qualcomm 307205 Mobile Firmware 215 Mobile Firmware315 5g Iot Modem Firmware+304 moreJun 17, 2026 Mar 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while processing RT proxy port register driver. |
1Qualcomm 65Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+62 moreJun 17, 2026 Feb 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
1Qualcomm 8Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcm8550 Firmware+5 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when malformed message payload is received from firmware. |
1Qualcomm 261315 5g Iot Modem Firmware Apq8017 FirmwareAqt1000 Firmware+258 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
1Qualcomm 1109206 Lte Modem Firmware Aqt1000 FirmwareAr8035 Firmware+107 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
1Qualcomm 118Snapdragon 425 Mobile Platform Firmware Snapdragon 427 Mobile Platform FirmwareSnapdragon 429 Mobile Platform Firmware+115 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and...Show more |
1Qualcomm 259315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+256 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio during playback with speaker protection. |
An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system. |
1Qualcomm 147Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+144 moreJun 17, 2026 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. |
1Qualcomm 143Apq5053 Aa Firmware Ar8035 FirmwareCsra6620 Firmware+140 moreJun 17, 2026 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while running invalid audio recording from ADSP. |
1Qualcomm 223315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+220 moreJun 17, 2026 Nov 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service at...Show more |
1Qualcomm 61Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+58 moreJun 17, 2026 Oct 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption in Modem while processing security related configuration before AS Security Exchange. |
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affect...Show more |
1Qualcomm 247Aqt1000 Firmware Ar8031 FirmwareAr9380 Firmware+244 moreJun 17, 2026 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
1Qualcomm 59205 Firmware 215 FirmwareAqt1000 Firmware+56 moreJun 17, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. |
1Qualcomm 266205 Firmware 215 Firmware315 5g Iot Firmware+263 moreJun 17, 2026 Jul 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacke...Show more |
An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacke...Show more |