Snapdragon 835 Mobile Pc Platform Firmware
by Qualcomm
CVEs (50)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28546 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. | ||
| CVE-2023-28559 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28558 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN handler while processing PhyID in Tx status handler. | ||
| CVE-2023-28557 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28549 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | ||
| CVE-2023-28544 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. | ||
| CVE-2023-21656 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2023-43519 | Hig | 0.47 | 7.3 | 0.00 | Feb 6, 2024 | Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. | ||
| CVE-2023-43518 | Hig | 0.47 | 7.3 | 0.00 | Feb 6, 2024 | Memory corruption in video while parsing invalid mp2 clip. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2023-33077 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. | ||
| CVE-2023-33069 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. | ||
| CVE-2023-33068 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. | ||
| CVE-2023-33067 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in SPS Application while exporting public key in sorter TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.47cvss 7.3epss 0.00
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
- risk 0.47cvss 7.3epss 0.00
Memory corruption in video while parsing invalid mp2 clip.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in HLOS while converting from authorization token to HIDL vector.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing IIR config data from AFE calibration block.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
Page 2 of 3