Sm7350 Ab Firmware
by Qualcomm
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21670 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. | ||
| CVE-2023-21657 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memoru corruption in Audio when ADSP sends input during record use case. | ||
| CVE-2023-21656 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. | ||
| CVE-2022-33264 | Hig | 0.51 | 7.9 | 0.00 | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | ||
| CVE-2023-33080 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | ||
| CVE-2023-33044 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Data modem while handling TLB control messages from the Network. | ||
| CVE-2023-33043 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem when a Beam switch request is made with a non-configured BWP. | ||
| CVE-2023-33042 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem after RRC Setup message is received. | ||
| CVE-2023-33047 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing no-inherit IES. | ||
| CVE-2023-33027 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. | ||
| CVE-2023-33026 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing a NAN management frame. | ||
| CVE-2023-21659 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | ||
| CVE-2023-21658 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. | ||
| CVE-2022-40536 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2022-33251 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to reachable assertion in Modem because of invalid network configuration. | ||
| CVE-2022-22060 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Assertion occurs while processing Reconfiguration message due to improper validation | ||
| CVE-2022-40504 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | ||
| CVE-2022-40508 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | ||
| CVE-2022-34144 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- risk 0.51cvss 7.8epss 0.00
Memoru corruption in Audio when ADSP sends input during record use case.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- risk 0.51cvss 7.9epss 0.00
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Data modem while handling TLB control messages from the Network.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem after RRC Setup message is received.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing no-inherit IES.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing rsn ies.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a NAN management frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing frames with missing header fields.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
- risk 0.49cvss 7.5epss 0.00
Assertion occurs while processing Reconfiguration message due to improper validation
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Page 2 of 3