Qrb5165m Firmware
by Qualcomm
CVEs (260)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35112 | Hig | 0.55 | 8.4 | 0.00 | Jun 14, 2022 | A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2021-30334 | Hig | 0.55 | 8.4 | 0.00 | Jun 14, 2022 | Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-30281 | Hig | 0.55 | 8.4 | 0.00 | Jun 14, 2022 | Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &… | ||
| CVE-2021-35105 | Hig | 0.55 | 8.4 | 0.00 | Apr 1, 2022 | Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-35077 | Hig | 0.55 | 8.4 | 0.00 | Feb 11, 2022 | Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-35068 | Hig | 0.55 | 8.4 | 0.01 | Feb 11, 2022 | Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,… | ||
| CVE-2021-30318 | Hig | 0.55 | 8.4 | 0.00 | Feb 11, 2022 | Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2024-38408 | Hig | 0.53 | 8.2 | 0.00 | Nov 4, 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | ||
| CVE-2023-28585 | Hig | 0.53 | 8.2 | 0.00 | Dec 5, 2023 | Memory corruption while loading an ELF segment in TEE Kernel. | ||
| CVE-2023-28545 | Hig | 0.53 | 8.2 | 0.00 | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. | ||
| CVE-2023-21669 | Hig | 0.53 | 8.2 | 0.00 | Jun 6, 2023 | Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address. | ||
| CVE-2022-40503 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | ||
| CVE-2022-33271 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure due to buffer over-read in WLAN while parsing NMF frame. | ||
| CVE-2022-33284 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while parsing BTM action frame. | ||
| CVE-2022-33283 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check. | ||
| CVE-2022-33255 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device. | ||
| CVE-2022-33252 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame. | ||
| CVE-2022-25746 | Hig | 0.53 | 8.1 | 0.00 | Jan 9, 2023 | Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping. | ||
| CVE-2022-33268 | Hig | 0.53 | 8.2 | 0.00 | Dec 13, 2022 | Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2022-33235 | Hig | 0.53 | 8.2 | 0.00 | Dec 13, 2022 | Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
- risk 0.55cvss 8.4epss 0.00
A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &…
- risk 0.55cvss 8.4epss 0.00
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.01
Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,…
- risk 0.55cvss 8.4epss 0.00
Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.53cvss 8.2epss 0.00
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- risk 0.53cvss 8.2epss 0.00
Memory corruption while loading an ELF segment in TEE Kernel.
- risk 0.53cvss 8.2epss 0.00
Memory corruption in TZ Secure OS while loading an app ELF.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
- risk 0.53cvss 8.1epss 0.00
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
Page 5 of 13