Qca6436 Firmware
by Qualcomm
CVEs (629)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21636 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory Corruption due to improper validation of array index in Linux while updating adn record. | ||
| CVE-2022-40524 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service. | ||
| CVE-2023-28577 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel… | ||
| CVE-2023-28575 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. | ||
| CVE-2023-21650 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length. | ||
| CVE-2023-21649 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in WLAN while running doDriverCmd for an unspecific command. | ||
| CVE-2023-21627 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in Trusted Execution Environment while calling service API with invalid address. | ||
| CVE-2023-21638 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Video while calling APIs with different instance ID than the one received in initialization. | ||
| CVE-2023-21637 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Linux while calling system configuration APIs. | ||
| CVE-2023-21635 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. | ||
| CVE-2023-21633 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | ||
| CVE-2023-21629 | Med | 0.44 | 6.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | ||
| CVE-2022-33267 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux while sending DRM request. | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33298 | Med | 0.44 | 6.7 | 0.00 | Apr 13, 2023 | Memory corruption due to use after free in Modem while modem initialization. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2022-33246 | Med | 0.44 | 6.7 | 0.00 | Feb 12, 2023 | Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id. | ||
| CVE-2022-33225 | Med | 0.44 | 6.7 | 0.00 | Feb 12, 2023 | Memory corruption due to use after free in trusted application environment. | ||
| CVE-2022-40519 | Med | 0.44 | 6.8 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer overread in Core |
- risk 0.44cvss 6.7epss 0.00
Memory Corruption due to improper validation of array index in Linux while updating adn record.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
- risk 0.44cvss 6.7epss 0.00
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel…
- risk 0.44cvss 6.7epss 0.00
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux while calling system configuration APIs.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
- risk 0.44cvss 6.8epss 0.00
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux while sending DRM request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in Modem while modem initialization.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in trusted application environment.
- risk 0.44cvss 6.8epss 0.00
Information disclosure due to buffer overread in Core
Page 27 of 32