Wcn3980 Firmware
by Qualcomm
CVEs (824)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2021-35123 | Hig | 0.57 | 8.8 | 0.00 | Jun 14, 2022 | Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT | ||
| CVE-2020-11269 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2020-11177 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2020-11303 | Hig | 0.56 | 8.6 | 0.01 | Oct 20, 2021 | Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2024-33044 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | ||
| CVE-2024-33060 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. | ||
| CVE-2024-33045 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | ||
| CVE-2024-33035 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | ||
| CVE-2024-33034 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | ||
| CVE-2024-33028 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. | ||
| CVE-2024-33027 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. | ||
| CVE-2024-33023 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | ||
| CVE-2024-33022 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while allocating memory in HGSL driver. | ||
| CVE-2024-33021 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while processing IOCTL call to set metainfo. | ||
| CVE-2024-23384 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. | ||
| CVE-2024-23383 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when kernel driver attempts to trigger hardware fences. | ||
| CVE-2024-23382 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while processing graphics kernel driver request to create DMA fence. | ||
| CVE-2024-23381 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU. | ||
| CVE-2024-21481 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.57cvss 8.8epss 0.00
Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT
- risk 0.57cvss 8.8epss 0.00
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.57cvss 8.8epss 0.00
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.56cvss 8.6epss 0.01
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when two threads try to map and unmap a single node simultaneously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory in HGSL driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing IOCTL call to set metainfo.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when kernel driver attempts to trigger hardware fences.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing graphics kernel driver request to create DMA fence.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Page 5 of 42