Qts110 Firmware
by Qualcomm
CVEs (72)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2023-33018 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. | ||
| CVE-2023-33017 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | ||
| CVE-2023-28551 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | ||
| CVE-2023-28550 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | ||
| CVE-2023-28546 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. | ||
| CVE-2023-28565 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | ||
| CVE-2022-25705 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response | ||
| CVE-2022-33233 | Hig | 0.51 | 7.8 | 0.00 | Feb 12, 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. | ||
| CVE-2024-23353 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||
| CVE-2023-21631 | Hig | 0.49 | 7.5 | 0.00 | Jul 4, 2023 | Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2022-33304 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. | ||
| CVE-2022-33294 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message. | ||
| CVE-2022-33223 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding. | ||
| CVE-2022-25739 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call | ||
| CVE-2022-25737 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to missing NULL check while reading packets received from local network | ||
| CVE-2022-25731 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to buffer over-read while processing packets from DNS server | ||
| CVE-2022-33213 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet | ||
| CVE-2022-25735 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Denial of service in modem due to missing null check while processing TCP or UDP packets from server |
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while using the UIM diag command to get the operators name.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in SPS Application while exporting public key in sorter TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
- risk 0.49cvss 7.5epss 0.00
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding.
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
- risk 0.49cvss 7.5epss 0.00
Information disclosure in modem due to missing NULL check while reading packets received from local network
- risk 0.49cvss 7.5epss 0.00
Information disclosure in modem due to buffer over-read while processing packets from DNS server
- risk 0.49cvss 7.5epss 0.00
Memory corruption in modem due to buffer overflow while processing a PPP packet
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
Page 3 of 4