Qcs4490 Firmware
by Qualcomm
CVEs (259)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2024-33042 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. | ||
| CVE-2024-33038 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | ||
| CVE-2024-23356 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption during session sign renewal request calls in HLOS. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-43550 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2024 | Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. | ||
| CVE-2023-43513 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | ||
| CVE-2023-33087 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Core while processing RX intent request. | ||
| CVE-2023-33018 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. | ||
| CVE-2023-33017 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | ||
| CVE-2023-28587 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. | ||
| CVE-2023-28551 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | ||
| CVE-2023-28550 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. | ||
| CVE-2023-28546 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. | ||
| CVE-2023-24850 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | ||
| CVE-2023-28573 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing WMI command parameters. | ||
| CVE-2023-28567 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when Alternative Frequency offset value is set to 255.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during session sign renewal request calls in HLOS.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Core while processing RX intent request.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while using the UIM diag command to get the operators name.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in SPS Application while exporting public key in sorter TA.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing WMI command parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command through WMI interfaces.
Page 6 of 13