Sxr1120 Firmware
by Qualcomm
CVEs (84)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33062 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2023-21659 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2023-43548 | Hig | 0.47 | 7.3 | 0.00 | Mar 4, 2024 | Memory corruption while parsing qcp clip with invalid chunk data size. | ||
| CVE-2023-43518 | Hig | 0.47 | 7.3 | 0.00 | Feb 6, 2024 | Memory corruption in video while parsing invalid mp2 clip. | ||
| CVE-2023-28556 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2023 | Cryptographic issue in HLOS during key management. | ||
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2020-11132 | Hig | 0.46 | 7.1 | 0.00 | Nov 12, 2020 | u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure… | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2023-33077 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. | ||
| CVE-2023-21629 | Med | 0.44 | 6.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2023-28568 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL when reception status handler is called. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a BTM request.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing frames with missing header fields.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.47cvss 7.3epss 0.00
Memory corruption while parsing qcp clip with invalid chunk data size.
- risk 0.47cvss 7.3epss 0.00
Memory corruption in video while parsing invalid mp2 clip.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS during key management.
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure…
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in HLOS while converting from authorization token to HIDL vector.
- risk 0.44cvss 6.8epss 0.00
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL when reception status handler is called.
Page 4 of 5