Fastconnect 7800 Firmware
by Qualcomm
CVEs (634)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28583 | Med | 0.44 | 6.7 | 0.00 | Jan 2, 2024 | Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address. | ||
| CVE-2023-28580 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache. | ||
| CVE-2023-28579 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length. | ||
| CVE-2023-22668 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Audio while invoking IOCTLs calls from the user-space. | ||
| CVE-2023-22383 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in camera while installing a fd for a particular DMA buffer. | ||
| CVE-2023-21634 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM. | ||
| CVE-2023-28570 | Med | 0.44 | 6.7 | 0.00 | Nov 7, 2023 | Memory corruption while processing audio effects. | ||
| CVE-2023-28577 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel… | ||
| CVE-2023-28575 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. | ||
| CVE-2023-21640 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Linux when the file upload API is called with parameters having large buffer. | ||
| CVE-2023-21639 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client. | ||
| CVE-2023-21638 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Video while calling APIs with different instance ID than the one received in initialization. | ||
| CVE-2023-21637 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory corruption in Linux while calling system configuration APIs. | ||
| CVE-2023-21635 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. | ||
| CVE-2023-21633 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | ||
| CVE-2023-21629 | Med | 0.44 | 6.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2025-27039 | Med | 0.43 | 6.6 | 0.00 | Oct 9, 2025 | Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request. | ||
| CVE-2025-21426 | Med | 0.43 | 6.6 | 0.00 | Jul 8, 2025 | Memory corruption while processing camera TPG write request. | ||
| CVE-2024-53018 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing the OIS packet parser. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in camera while installing a fd for a particular DMA buffer.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing audio effects.
- risk 0.44cvss 6.7epss 0.00
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel…
- risk 0.44cvss 6.7epss 0.00
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux while calling system configuration APIs.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
- risk 0.44cvss 6.8epss 0.00
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing camera TPG write request.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing the OIS packet parser.
Page 27 of 32