Snapdragon Ar2 Gen1 Platform Firmware
by Qualcomm
CVEs (162)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33107 | Hig | 0.67 | 8.4 | 0.01 | KEV | Dec 5, 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | |
| CVE-2023-33106 | Hig | 0.67 | 8.4 | 0.01 | KEV | Dec 5, 2023 | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | |
| CVE-2023-33045 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute. | ||
| CVE-2023-33028 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. | ||
| CVE-2023-33063 | Hig | 0.63 | 7.8 | 0.01 | KEV | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. | |
| CVE-2023-33072 | Cri | 0.60 | 9.3 | 0.00 | Feb 6, 2024 | Memory corruption in Core while processing control functions. | ||
| CVE-2023-33030 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in HLOS while running playready use-case. | ||
| CVE-2022-33288 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | ||
| CVE-2022-33269 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | ||
| CVE-2022-33231 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. | ||
| CVE-2023-28574 | Cri | 0.59 | 9.0 | 0.00 | Nov 7, 2023 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | ||
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2023-43534 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | ||
| CVE-2023-43520 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-33044 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | ||
| CVE-2024-33034 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | ||
| CVE-2024-33023 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | ||
| CVE-2024-23384 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. | ||
| CVE-2024-23382 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while processing graphics kernel driver request to create DMA fence. |
- risk 0.67cvss 8.4epss 0.01
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
- risk 0.67cvss 8.4epss 0.01
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
- risk 0.63cvss 7.8epss 0.01
Memory corruption in DSP Services during a remote call from HLOS to DSP.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core while processing control functions.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in HLOS while running playready use-case.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to double free in core while initializing the encryption key.
- risk 0.59cvss 9.0epss 0.00
Memory corruption in core services when Diag handler receives a command to configure event listeners.
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.56cvss 8.6epss 0.00
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- risk 0.56cvss 8.6epss 0.00
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing graphics kernel driver request to create DMA fence.
Page 1 of 9