Mdm9207 Firmware
by Qualcomm
CVEs (83)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11166 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2020-11177 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2022-25694 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | ||
| CVE-2022-25695 | Hig | 0.55 | 8.4 | 0.00 | Dec 13, 2022 | Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice… | ||
| CVE-2022-25682 | Hig | 0.55 | 8.4 | 0.00 | Dec 13, 2022 | Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2021-30261 | Hig | 0.55 | 8.4 | 0.00 | Sep 17, 2021 | Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2022-33295 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length. | ||
| CVE-2022-33258 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read in modem while reading configuration parameters. | ||
| CVE-2022-33228 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header. | ||
| CVE-2022-33222 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. | ||
| CVE-2022-25747 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message | ||
| CVE-2022-25730 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to improper check of IP type while processing DNS server query | ||
| CVE-2022-25726 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet | ||
| CVE-2022-33229 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. | ||
| CVE-2022-25738 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received | ||
| CVE-2022-25732 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure in modem due to buffer over read in dns client due to missing length check | ||
| CVE-2022-25728 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure in modem due to buffer over-read while processing response from DNS server | ||
| CVE-2020-11285 | Hig | 0.53 | 8.2 | 0.01 | May 7, 2021 | Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2020-11251 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2021 | Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2020-11191 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2021 | Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
- risk 0.59cvss 9.1epss 0.01
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.57cvss 8.8epss 0.00
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- risk 0.55cvss 8.4epss 0.00
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.55cvss 8.4epss 0.00
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in modem while reading configuration parameters.
- risk 0.53cvss 8.2epss 0.00
Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read while parsing DNS response packets in Modem.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to improper check of IP type while processing DNS server query
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to buffer over-red while performing checksum of packet received
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to buffer over read in dns client due to missing length check
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to buffer over-read while processing response from DNS server
- risk 0.53cvss 8.2epss 0.01
Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
- risk 0.53cvss 8.2epss 0.01
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
- risk 0.53cvss 8.2epss 0.01
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
Page 2 of 5