Wcn3998 Firmware
by Qualcomm
CVEs (300)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2021-35101 | Hig | 0.46 | 7.1 | 0.00 | Jun 14, 2022 | Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile | ||
| CVE-2021-1935 | Hig | 0.46 | 7.1 | 0.00 | Sep 9, 2021 | Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2020-11262 | Hig | 0.46 | 7.0 | 0.00 | Jun 9, 2021 | A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2020-11250 | Hig | 0.46 | 7.0 | 0.00 | Jun 9, 2021 | Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon… | ||
| CVE-2020-11161 | Hig | 0.46 | 7.1 | 0.00 | Jun 9, 2021 | Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external components in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11290 | Hig | 0.46 | 7.0 | 0.00 | Mar 17, 2021 | Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2023-21663 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory Corruption while accessing metadata in Display. | ||
| CVE-2023-21644 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request. | ||
| CVE-2022-40524 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service. | ||
| CVE-2023-21650 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length. | ||
| CVE-2023-21648 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in RIL while trying to send apdu packet. | ||
| CVE-2023-21627 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in Trusted Execution Environment while calling service API with invalid address. | ||
| CVE-2022-33230 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-25712 | Med | 0.44 | 6.7 | 0.00 | Dec 13, 2022 | Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-35092 | Med | 0.44 | 6.7 | 0.00 | Jun 14, 2022 | Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2021-30266 | Med | 0.44 | 6.7 | 0.00 | Nov 12, 2021 | Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2021-30265 | Med | 0.44 | 6.7 | 0.00 | Nov 12, 2021 | Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing Filter and Route statistics in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile
- risk 0.46cvss 7.1epss 0.00
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon…
- risk 0.46cvss 7.0epss 0.00
A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- risk 0.46cvss 7.0epss 0.00
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…
- risk 0.46cvss 7.1epss 0.00
Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external components in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.46cvss 7.0epss 0.00
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.44cvss 6.7epss 0.00
Memory Corruption while accessing metadata in Display.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in RIL while trying to send apdu packet.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.44cvss 6.7epss 0.00
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.44cvss 6.7epss 0.00
Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.44cvss 6.7epss 0.00
Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing Filter and Route statistics in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
Page 13 of 15