Snapdragon 855\+860 Mobile Platform Firmware
by Qualcomm
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33107 | Hig | 0.67 | 8.4 | 0.01 | KEV | Dec 5, 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | |
| CVE-2023-22388 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. | ||
| CVE-2023-33072 | Cri | 0.60 | 9.3 | 0.00 | Feb 6, 2024 | Memory corruption in Core while processing control functions. | ||
| CVE-2023-33032 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. | ||
| CVE-2023-33030 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in HLOS while running playready use-case. | ||
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33092 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | ||
| CVE-2023-33088 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption when processing cmd parameters while parsing vdev. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. | ||
| CVE-2024-38408 | Hig | 0.53 | 8.2 | 0.00 | Nov 4, 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | ||
| CVE-2023-28585 | Hig | 0.53 | 8.2 | 0.00 | Dec 5, 2023 | Memory corruption while loading an ELF segment in TEE Kernel. | ||
| CVE-2023-33120 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. | ||
| CVE-2023-33110 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | ||
| CVE-2023-28587 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. | ||
| CVE-2023-28550 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | ||
| CVE-2023-28546 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. | ||
| CVE-2023-28557 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28544 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
- risk 0.67cvss 8.4epss 0.01
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
- risk 0.64cvss 9.8epss 0.00
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core while processing control functions.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in HLOS while running playready use-case.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when processing cmd parameters while parsing vdev.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
- risk 0.53cvss 8.2epss 0.00
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- risk 0.53cvss 8.2epss 0.00
Memory corruption while loading an ELF segment in TEE Kernel.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
- risk 0.51cvss 7.8epss 0.00
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in SPS Application while exporting public key in sorter TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Page 1 of 3