Qcs6125 Firmware
by Qualcomm
CVEs (261)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11276 | Cri | 0.59 | 9.1 | 0.01 | Feb 22, 2021 | Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… | ||
| CVE-2020-11275 | Cri | 0.59 | 9.1 | 0.01 | Feb 22, 2021 | Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2020-11269 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2020-11177 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-33034 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | ||
| CVE-2024-33028 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. | ||
| CVE-2024-23383 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when kernel driver attempts to trigger hardware fences. | ||
| CVE-2024-23381 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU. | ||
| CVE-2024-23373 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | ||
| CVE-2024-23372 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | ||
| CVE-2024-23351 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. | ||
| CVE-2024-21471 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. | ||
| CVE-2024-21468 | Hig | 0.55 | 8.4 | 0.00 | Apr 1, 2024 | Memory corruption when there is failed unmap operation in GPU. | ||
| CVE-2023-43546 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption while invoking HGSL IOCTL context create. | ||
| CVE-2023-33066 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. | ||
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33088 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption when processing cmd parameters while parsing vdev. | ||
| CVE-2023-33022 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. |
- risk 0.59cvss 9.1epss 0.01
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
- risk 0.59cvss 9.1epss 0.01
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.57cvss 8.8epss 0.00
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.57cvss 8.8epss 0.00
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when kernel driver attempts to trigger hardware fences.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when there is failed unmap operation in GPU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking HGSL IOCTL context create.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while processing RT proxy port register driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when processing cmd parameters while parsing vdev.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
Page 3 of 14