Sa8155p Firmware
by Qualcomm
CVEs (938)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11154 | Hig | 0.57 | 8.8 | 0.01 | Nov 2, 2020 | u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon… | ||
| CVE-2023-43534 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | ||
| CVE-2023-43520 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. | ||
| CVE-2020-11303 | Hig | 0.56 | 8.6 | 0.01 | Oct 20, 2021 | Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2024-45555 | Hig | 0.55 | 8.4 | 0.00 | Jan 6, 2025 | Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image. | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-33044 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | ||
| CVE-2024-38399 | Hig | 0.55 | 8.4 | 0.00 | Oct 7, 2024 | Memory corruption while processing user packets to generate page faults. | ||
| CVE-2024-33060 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. | ||
| CVE-2024-33045 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | ||
| CVE-2024-33035 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | ||
| CVE-2024-23365 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while releasing shared resources in MinkSocket listener thread. | ||
| CVE-2024-33034 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | ||
| CVE-2024-33028 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. | ||
| CVE-2024-33027 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. | ||
| CVE-2024-33023 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | ||
| CVE-2024-33022 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while allocating memory in HGSL driver. | ||
| CVE-2024-33021 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while processing IOCTL call to set metainfo. | ||
| CVE-2024-23384 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. | ||
| CVE-2024-23383 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when kernel driver attempts to trigger hardware fences. |
- risk 0.57cvss 8.8epss 0.01
u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…
- risk 0.56cvss 8.6epss 0.00
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- risk 0.56cvss 8.6epss 0.00
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
- risk 0.56cvss 8.6epss 0.01
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing user packets to generate page faults.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when two threads try to map and unmap a single node simultaneously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while releasing shared resources in MinkSocket listener thread.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory in HGSL driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing IOCTL call to set metainfo.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when kernel driver attempts to trigger hardware fences.
Page 7 of 47