Wcn3998 Firmware
by Qualcomm
CVEs (527)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11203 | Hig | 0.46 | 7.1 | 0.00 | Feb 22, 2021 | Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-30299 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. | ||
| CVE-2023-33024 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory corruption while sending SMS from AP firmware. | ||
| CVE-2023-21663 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory Corruption while accessing metadata in Display. | ||
| CVE-2023-21654 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption in Audio during playback session with audio effects enabled. | ||
| CVE-2023-21644 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request. | ||
| CVE-2023-21636 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory Corruption due to improper validation of array index in Linux while updating adn record. | ||
| CVE-2022-40524 | Med | 0.44 | 6.7 | 0.00 | Sep 5, 2023 | Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service. | ||
| CVE-2023-21650 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length. | ||
| CVE-2023-21649 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in WLAN while running doDriverCmd for an unspecific command. | ||
| CVE-2023-21648 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in RIL while trying to send apdu packet. | ||
| CVE-2023-21627 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in Trusted Execution Environment while calling service API with invalid address. | ||
| CVE-2022-33267 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux while sending DRM request. | ||
| CVE-2022-33263 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to use after free in Core when multiple DCI clients register and deregister. | ||
| CVE-2022-33230 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33226 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications. | ||
| CVE-2022-33224 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33298 | Med | 0.44 | 6.7 | 0.00 | Apr 13, 2023 | Memory corruption due to use after free in Modem while modem initialization. |
- risk 0.46cvss 7.1epss 0.00
Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.44cvss 6.7epss 0.00
Possible out of bound access in audio module due to lack of validation of user provided input.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending SMS from AP firmware.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption while accessing metadata in Display.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio during playback session with audio effects enabled.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption due to improper validation of array index in Linux while updating adn record.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in RIL while trying to send apdu packet.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux while sending DRM request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in Core when multiple DCI clients register and deregister.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in Modem while modem initialization.
Page 22 of 27