Qca9888 Firmware
by Qualcomm
CVEs (296)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30269 | Hig | 0.47 | 7.3 | 0.00 | Jan 3, 2022 | Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,… | ||
| CVE-2020-11263 | Hig | 0.47 | 7.3 | 0.00 | Jan 3, 2022 | An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-1909 | Hig | 0.47 | 7.3 | 0.00 | Sep 9, 2021 | Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2020-11252 | Hig | 0.47 | 7.2 | 0.00 | Apr 7, 2021 | Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. | ||
| CVE-2024-21462 | Hig | 0.46 | 7.1 | 0.00 | Jul 1, 2024 | Transient DOS while loading the TA ELF file. | ||
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2022-40523 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Information disclosure in Kernel due to indirect branch misprediction. | ||
| CVE-2022-22076 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. | ||
| CVE-2021-30278 | Hig | 0.46 | 7.1 | 0.00 | Jan 3, 2022 | Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and… | ||
| CVE-2021-1894 | Hig | 0.46 | 7.1 | 0.00 | Jan 3, 2022 | Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and… | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2024-21482 | Med | 0.44 | 6.8 | 0.00 | Jul 1, 2024 | Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image. | ||
| CVE-2022-40519 | Med | 0.44 | 6.8 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer overread in Core | ||
| CVE-2022-40518 | Med | 0.44 | 6.8 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer overread in Core | ||
| CVE-2022-25677 | Med | 0.44 | 6.7 | 0.00 | Dec 13, 2022 | Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2022-25666 | Med | 0.44 | 6.7 | 0.00 | Oct 19, 2022 | Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-30325 | Med | 0.44 | 6.7 | 0.00 | Feb 11, 2022 | Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired… | ||
| CVE-2021-30324 | Med | 0.44 | 6.7 | 0.00 | Feb 11, 2022 | Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2021-30313 | Med | 0.44 | 6.7 | 0.00 | Jan 13, 2022 | Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… |
- risk 0.47cvss 7.3epss 0.00
Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,…
- risk 0.47cvss 7.3epss 0.00
An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
- risk 0.47cvss 7.3epss 0.00
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.47cvss 7.2epss 0.00
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
- risk 0.46cvss 7.1epss 0.00
Transient DOS while loading the TA ELF file.
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
Information disclosure in Kernel due to indirect branch misprediction.
- risk 0.46cvss 7.1epss 0.00
information disclosure due to cryptographic issue in Core during RPMB read request.
- risk 0.46cvss 7.1epss 0.00
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…
- risk 0.46cvss 7.1epss 0.00
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.8epss 0.00
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.
- risk 0.44cvss 6.8epss 0.00
Information disclosure due to buffer overread in Core
- risk 0.44cvss 6.8epss 0.00
Information disclosure due to buffer overread in Core
- risk 0.44cvss 6.7epss 0.00
Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- risk 0.44cvss 6.7epss 0.00
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…
- risk 0.44cvss 6.7epss 0.00
Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.44cvss 6.7epss 0.00
Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
Page 13 of 15