Sa8775p Firmware
by Qualcomm
CVEs (263)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33019 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the received TID-to-link mapping action frame. | ||
| CVE-2024-33018 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. | ||
| CVE-2024-33015 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-33013 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. | ||
| CVE-2024-33012 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | ||
| CVE-2024-33011 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | ||
| CVE-2024-33010 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. | ||
| CVE-2024-21479 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS during music playback of ALAC content. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-43522 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | ||
| CVE-2023-33098 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing WPA IES, when it is passed with length more than expected size. | ||
| CVE-2023-33089 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS when processing a NULL buffer while parsing WLAN vdev. | ||
| CVE-2025-21425 | Hig | 0.47 | 7.3 | 0.00 | Apr 7, 2025 | Memory corruption may occur due top improper access control in HAB process. | ||
| CVE-2024-21469 | Hig | 0.47 | 7.3 | 0.00 | Jul 1, 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | ||
| CVE-2024-21480 | Hig | 0.47 | 7.3 | 0.00 | May 6, 2024 | Memory corruption while playing audio file having large-sized input buffer. | ||
| CVE-2024-21463 | Hig | 0.47 | 7.3 | 0.00 | Apr 1, 2024 | Memory corruption while processing Codec2 during v13k decoder pitch synthesis. | ||
| CVE-2023-43548 | Hig | 0.47 | 7.3 | 0.00 | Mar 4, 2024 | Memory corruption while parsing qcp clip with invalid chunk data size. | ||
| CVE-2023-43519 | Hig | 0.47 | 7.3 | 0.00 | Feb 6, 2024 | Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the received TID-to-link mapping action frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS during music playback of ALAC content.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
- risk 0.47cvss 7.3epss 0.00
Memory corruption may occur due top improper access control in HAB process.
- risk 0.47cvss 7.3epss 0.00
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
- risk 0.47cvss 7.3epss 0.00
Memory corruption while playing audio file having large-sized input buffer.
- risk 0.47cvss 7.3epss 0.00
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
- risk 0.47cvss 7.3epss 0.00
Memory corruption while parsing qcp clip with invalid chunk data size.
- risk 0.47cvss 7.3epss 0.00
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
Page 10 of 14