CVEs (361)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 285315 5g Iot Firmware Aqt1000 FirmwareAr8031 Firmware+282 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while handling command through WMI interfaces. |
1Qualcomm 2929205 Lte Firmware Apq8017 FirmwareApq8064au Firmware+289 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
1Qualcomm 247Aqt1000 Firmware Ar8031 FirmwareAr9380 Firmware+244 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
1Qualcomm 2678098 Firmware 8998 FirmwareApq5053 Aa Firmware+264 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
1Qualcomm 211Aqt1000 Firmware Ar8031 FirmwareAr9380 Firmware+208 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. |
1Qualcomm 195315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+192 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN handler while processing PhyID in Tx status handler. |
1Qualcomm 273315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+270 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. |
1Qualcomm 220315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+217 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. |
1Qualcomm 179Aqt1000 Firmware Ar8035 FirmwareAr9380 Firmware+176 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. |
1Qualcomm 205Aqt1000 Firmware Ar9380 FirmwareCsr8811 Firmware+202 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. |
1Qualcomm 43Qca6390 Firmware Qca6391 FirmwareQca6426 Firmware+40 moreNov 21, 2024 Sep 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. |
1Qualcomm 137Aqt1000 Firmware Ar8035 FirmwareFsm10056 Firmware+134 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption in Core Platform while printing the response buffer in log. |
1Qualcomm 136Aqt1000 Firmware Ar8035 FirmwareFsm10056 Firmware+133 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Core Platform while printing the response buffer in log. |
1Qualcomm 56Apq8096au Firmware Aqt1000 FirmwareMdm9150 Firmware+53 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio during playback session with audio effects enabled. |
1Qualcomm 259315 5g Iot Modem Firmware Apq5053 Aa FirmwareAqt1000 Firmware+256 moreNov 21, 2024 Sep 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. |
1Qualcomm 30Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 moreNov 21, 2024 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEAS...Show more |
1Qualcomm 30Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 moreNov 21, 2024 Aug 8, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), caus...Show more |
1Qualcomm 59205 Firmware 215 FirmwareAqt1000 Firmware+56 moreNov 21, 2024 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. |
1Qualcomm 183315 5g Iot Modem Firmware 8098 Firmware8998 Firmware+180 moreNov 21, 2024 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while allocating memory in COmxApeDec module in Audio. |
1Qualcomm 172Apq8009 Firmware Apq8017 FirmwareApq8096au Firmware+169 moreNov 21, 2024 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption in Audio while playing amrwbplus clips with modified content. |