← Back

Wcn3988 Firmware

wcn3988_firmware

Vendor: Qualcomm • 886 CVEs

CVEs (886)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
66Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6800 Firmware+63 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while handling payloads from remote ESL.
1Qualcomm
2678098 Firmware
8998 FirmwareApq5053 Aa Firmware+264 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
1Qualcomm
211Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+208 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
1Qualcomm
195315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+192 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
1Qualcomm
273315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+270 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
1Qualcomm
220315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+217 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
1Qualcomm
205Aqt1000 Firmware
Ar9380 FirmwareCsr8811 Firmware+202 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
1Qualcomm
130Aqt1000 Firmware
Csra6620 FirmwareCsra6640 Firmware+127 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
1Qualcomm
43Qca6390 Firmware
Qca6391 FirmwareQca6426 Firmware+40 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
1Qualcomm
38Aqt1000 Firmware
Qca6420 FirmwareQca6430 Firmware+35 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption while accessing metadata in Display.
1Qualcomm
31Qca6391 Firmware
Qca6574au FirmwareQca6696 Firmware+28 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while validating and mapping metadata.
1Qualcomm
56Apq8096au Firmware
Aqt1000 FirmwareMdm9150 Firmware+53 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio during playback session with audio effects enabled.
1Qualcomm
54Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+51 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in Modem while processing invalid System Information Block 1.
1Qualcomm
51Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+48 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
1Qualcomm
51Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+48 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption due to improper validation of array index in Linux while updating adn record.
1Qualcomm
38Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+35 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
1Qualcomm
259315 5g Iot Modem Firmware
Apq5053 Aa FirmwareAqt1000 Firmware+256 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
1Qualcomm
45Aqt1000 Firmware
Qam8295p FirmwareQca6390 Firmware+42 more
Nov 21, 2024
Sep 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in Automotive multimedia due to buffer over-read.
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEAS...Show more
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.Show less
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Nov 21, 2024
Aug 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), caus...Show more
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.Show less