Sm4350 Ac Firmware
by Qualcomm
CVEs (64)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24855 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Memory corruption in Modem while processing security related configuration before AS Security Exchange. | ||
| CVE-2023-33063 | Hig | 0.63 | 7.8 | 0.01 | KEV | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. | |
| CVE-2022-33231 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. | ||
| CVE-2023-33054 | Cri | 0.59 | 9.1 | 0.00 | Dec 5, 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. | ||
| CVE-2023-28540 | Cri | 0.59 | 9.1 | 0.00 | Oct 3, 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | ||
| CVE-2024-23380 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while handling user packets during VBO bind operation. | ||
| CVE-2024-23373 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | ||
| CVE-2024-23372 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | ||
| CVE-2024-21461 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. | ||
| CVE-2023-33022 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. | ||
| CVE-2023-33029 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in DSP Service during a remote call from HLOS to DSP. | ||
| CVE-2022-33275 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. | ||
| CVE-2023-21628 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | ||
| CVE-2022-40507 | Hig | 0.55 | 8.4 | 0.01 | Jun 6, 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. | ||
| CVE-2023-21665 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory corruption in Graphics while importing a file. | ||
| CVE-2022-40532 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | ||
| CVE-2023-24849 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | ||
| CVE-2023-24848 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | ||
| CVE-2023-22385 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | ||
| CVE-2022-40503 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
- risk 0.64cvss 9.8epss 0.01
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
- risk 0.63cvss 7.8epss 0.01
Memory corruption in DSP Services during a remote call from HLOS to DSP.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to double free in core while initializing the encryption key.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while handling user packets during VBO bind operation.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in DSP Service during a remote call from HLOS to DSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
- risk 0.55cvss 8.4epss 0.01
Memory corruption due to double free in Core while mapping HLOS address to the list.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Graphics while importing a file.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- risk 0.53cvss 8.2epss 0.00
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Page 1 of 4