Qcn6024 Firmware
by Qualcomm
CVEs (436)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25748 | Cri | 0.64 | 9.8 | 0.00 | Oct 19, 2022 | Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… | ||
| CVE-2022-25720 | Cri | 0.64 | 9.8 | 0.00 | Oct 19, 2022 | Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2021-1976 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2021 | A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired… | ||
| CVE-2021-1972 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2021 | Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,… | ||
| CVE-2021-1965 | Cri | 0.64 | 9.8 | 0.03 | Jul 13, 2021 | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2020-11134 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2021 | Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute inside a NAN management frame are not Properly validated in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… | ||
| CVE-2026-21385 | Hig | 0.63 | 7.8 | 0.01 | KEV | Mar 2, 2026 | Memory corruption while using alignments for memory allocation. | |
| CVE-2023-33063 | Hig | 0.63 | 7.8 | 0.01 | KEV | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. | |
| CVE-2023-43556 | Cri | 0.60 | 9.3 | 0.00 | Jun 3, 2024 | Memory corruption in Hypervisor when platform information mentioned is not aligned. | ||
| CVE-2023-28578 | Cri | 0.60 | 9.3 | 0.00 | Mar 4, 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. | ||
| CVE-2023-33072 | Cri | 0.60 | 9.3 | 0.00 | Feb 6, 2024 | Memory corruption in Core while processing control functions. | ||
| CVE-2023-33032 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. | ||
| CVE-2023-33030 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in HLOS while running playready use-case. | ||
| CVE-2023-21651 | Cri | 0.60 | 9.3 | 0.00 | Aug 8, 2023 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. | ||
| CVE-2022-33288 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | ||
| CVE-2022-33269 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | ||
| CVE-2022-33231 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. | ||
| CVE-2022-33257 | Cri | 0.60 | 9.3 | 0.00 | Mar 10, 2023 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | ||
| CVE-2022-33232 | Cri | 0.60 | 9.3 | 0.00 | Feb 12, 2023 | Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory. | ||
| CVE-2021-30275 | Cri | 0.60 | 9.3 | 0.00 | Jan 3, 2022 | Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired… |
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.64cvss 9.8epss 0.01
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…
- risk 0.64cvss 9.8epss 0.03
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
- risk 0.64cvss 9.8epss 0.01
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup attribute inside a NAN management frame are not Properly validated in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,…
- risk 0.63cvss 7.8epss 0.01
Memory corruption while using alignments for memory allocation.
- risk 0.63cvss 7.8epss 0.01
Memory corruption in DSP Services during a remote call from HLOS to DSP.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Hypervisor when platform information mentioned is not aligned.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core Services while executing the command for removing a single event listener.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core while processing control functions.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in HLOS while running playready use-case.
- risk 0.60cvss 9.3epss 0.00
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to double free in core while initializing the encryption key.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
- risk 0.60cvss 9.3epss 0.00
Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…
Page 2 of 22