Sd835 Firmware
by Qualcomm
CVEs (179)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11159 | Cri | 0.59 | 9.1 | 0.01 | Jun 9, 2021 | Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon… | ||
| CVE-2020-11190 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11189 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11171 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11166 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2020-11276 | Cri | 0.59 | 9.1 | 0.01 | Feb 22, 2021 | Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… | ||
| CVE-2020-11275 | Cri | 0.59 | 9.1 | 0.01 | Feb 22, 2021 | Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2020-11269 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2020-11177 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-23373 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | ||
| CVE-2024-21471 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. | ||
| CVE-2024-21468 | Hig | 0.55 | 8.4 | 0.00 | Apr 1, 2024 | Memory corruption when there is failed unmap operation in GPU. | ||
| CVE-2023-33066 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. | ||
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33092 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | ||
| CVE-2023-22666 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. | ||
| CVE-2023-22667 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | ||
| CVE-2022-40531 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. | ||
| CVE-2022-25694 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.59cvss 9.1epss 0.01
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
- risk 0.59cvss 9.1epss 0.01
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.57cvss 8.8epss 0.00
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.57cvss 8.8epss 0.00
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when there is failed unmap operation in GPU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while processing RT proxy port register driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while playing amrwbplus clips with modified content.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while allocating the ion buffer during the music playback.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Page 2 of 9