Wsa8830 Firmware
by Qualcomm
CVEs (1,121)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33039 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service. | ||
| CVE-2024-33036 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | ||
| CVE-2021-30299 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. | ||
| CVE-2024-33033 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while processing IOCTL calls to unmap the buffers. | ||
| CVE-2024-33032 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. | ||
| CVE-2024-33030 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size. | ||
| CVE-2024-23386 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | memory corruption when WiFi display APIs are invoked with large random inputs. | ||
| CVE-2024-23377 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver. | ||
| CVE-2024-23379 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario. | ||
| CVE-2024-23376 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. | ||
| CVE-2024-23375 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption during the network scan request. | ||
| CVE-2024-23374 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. | ||
| CVE-2024-23370 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2023-43544 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption when IPC callback handle is used after it has been released during register callback by another thread. | ||
| CVE-2023-43543 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object. | ||
| CVE-2023-43527 | Med | 0.44 | 6.8 | 0.00 | May 6, 2024 | Information disclosure while parsing dts header atom in Video. | ||
| CVE-2023-43521 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when multiple listeners are being registered with the same file descriptor. | ||
| CVE-2023-33077 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. | ||
| CVE-2023-33069 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- risk 0.44cvss 6.7epss 0.00
Possible out of bound access in audio module due to lack of validation of user provided input.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing IOCTL calls to unmap the buffers.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
- risk 0.44cvss 6.7epss 0.00
memory corruption when WiFi display APIs are invoked with large random inputs.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
- risk 0.44cvss 6.7epss 0.00
Memory corruption during the network scan request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.
- risk 0.44cvss 6.8epss 0.00
Information disclosure while parsing dts header atom in Video.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple listeners are being registered with the same file descriptor.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in HLOS while converting from authorization token to HIDL vector.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
Page 46 of 57