Sg4150p Firmware
by Qualcomm
CVEs (226)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33092 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | ||
| CVE-2023-33088 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption when processing cmd parameters while parsing vdev. | ||
| CVE-2023-33022 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. | ||
| CVE-2023-33029 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in DSP Service during a remote call from HLOS to DSP. | ||
| CVE-2023-28538 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | ||
| CVE-2022-33275 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. | ||
| CVE-2023-21672 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions. | ||
| CVE-2023-21628 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | ||
| CVE-2022-40507 | Hig | 0.55 | 8.4 | 0.01 | Jun 6, 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. | ||
| CVE-2023-21630 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. | ||
| CVE-2022-40532 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | ||
| CVE-2022-40531 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. | ||
| CVE-2022-25694 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | ||
| CVE-2022-25655 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. | ||
| CVE-2022-33277 | Hig | 0.55 | 8.4 | 0.00 | Feb 12, 2023 | Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. | ||
| CVE-2025-21488 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. | ||
| CVE-2025-21487 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | ||
| CVE-2025-21484 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. |
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when processing cmd parameters while parsing vdev.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in DSP Service during a remote call from HLOS to DSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
- risk 0.55cvss 8.4epss 0.01
Memory corruption due to double free in Core while mapping HLOS address to the list.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Page 3 of 12