Snapdragon 208 Processor Firmware
by Qualcomm
CVEs (40)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38423 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU page table switch. | ||
| CVE-2024-38422 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | ||
| CVE-2023-33120 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. | ||
| CVE-2023-33018 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. | ||
| CVE-2023-33017 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | ||
| CVE-2023-28551 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | ||
| CVE-2023-28550 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | ||
| CVE-2023-33059 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. | ||
| CVE-2023-33031 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | ||
| CVE-2022-33264 | Hig | 0.51 | 7.9 | 0.00 | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | ||
| CVE-2024-23385 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. | ||
| CVE-2024-23358 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. | ||
| CVE-2024-23353 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2022-22076 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2024-33043 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU page table switch.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while using the UIM diag command to get the operators name.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio while processing the VOC packet data from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
- risk 0.51cvss 7.9epss 0.00
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.46cvss 7.1epss 0.00
information disclosure due to cryptographic issue in Core during RPMB read request.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Page 2 of 2