Sxr2130 Firmware
by Qualcomm
CVEs (356)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33068 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. | ||
| CVE-2023-33067 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. | ||
| CVE-2023-33038 | Med | 0.44 | 6.7 | 0.00 | Jan 2, 2024 | Memory corruption while receiving a message in Bus Socket Transport Server. | ||
| CVE-2023-22383 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in camera while installing a fd for a particular DMA buffer. | ||
| CVE-2023-21634 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM. | ||
| CVE-2023-28570 | Med | 0.44 | 6.7 | 0.00 | Nov 7, 2023 | Memory corruption while processing audio effects. | ||
| CVE-2023-28577 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel… | ||
| CVE-2023-28575 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. | ||
| CVE-2023-21637 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Linux while calling system configuration APIs. | ||
| CVE-2023-21635 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. | ||
| CVE-2023-21629 | Med | 0.44 | 6.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2024-53013 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing voice call registration with user. | ||
| CVE-2024-45570 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. | ||
| CVE-2024-45562 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. | ||
| CVE-2024-45543 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while accessing MSM channel map and mixer functions. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing IIR config data from AFE calibration block.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while receiving a message in Bus Socket Transport Server.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in camera while installing a fd for a particular DMA buffer.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing audio effects.
- risk 0.44cvss 6.7epss 0.00
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel…
- risk 0.44cvss 6.7epss 0.00
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux while calling system configuration APIs.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
- risk 0.44cvss 6.8epss 0.00
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing voice call registration with user.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
- risk 0.43cvss 6.6epss 0.00
Memory corruption during concurrent access to server info object due to unprotected critical field.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while accessing MSM channel map and mixer functions.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
Page 16 of 18