Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43535 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger. | ||
| CVE-2023-43532 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Memory corruption while reading ACPI config through the user mode app. | ||
| CVE-2023-43517 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Memory corruption in Automotive Multimedia due to improper access control in HAB. | ||
| CVE-2023-43514 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. | ||
| CVE-2023-33114 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. | ||
| CVE-2023-33113 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. | ||
| CVE-2023-33108 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued. | ||
| CVE-2023-33094 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption while running VK synchronization with KASAN enabled. | ||
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33092 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | ||
| CVE-2023-33088 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption when processing cmd parameters while parsing vdev. | ||
| CVE-2023-33071 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities. | ||
| CVE-2023-33053 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in Kernel while parsing metadata. | ||
| CVE-2023-33022 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. | ||
| CVE-2023-33074 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory corruption in Audio when SSR event is triggered after music playback is stopped. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. | ||
| CVE-2023-33039 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in Automotive Display while destroying the image handle created using connected display driver. | ||
| CVE-2023-33029 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in DSP Service during a remote call from HLOS to DSP. | ||
| CVE-2023-24853 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while registering for key provisioning notify. | ||
| CVE-2023-24844 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range. | ||
| CVE-2023-33021 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption in Graphics while processing user packets for command submission. | ||
| CVE-2023-28538 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region. | ||
| CVE-2022-40534 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption due to improper validation of array index in Audio. | ||
| CVE-2022-33275 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. | ||
| CVE-2023-28537 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. | ||
| CVE-2023-22666 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. | ||
| CVE-2023-22667 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | ||
| CVE-2023-21672 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions. | ||
| CVE-2023-21632 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in Automotive GPU while querying a gsl memory node. | ||
| CVE-2023-21628 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | ||
| CVE-2022-40522 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in Linux Networking due to double free while handling a hyp-assign. | ||
| CVE-2022-40507 | Hig | 0.55 | 8.4 | 0.01 | Jun 6, 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. | ||
| CVE-2022-33307 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed. | ||
| CVE-2023-21666 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | ||
| CVE-2023-21665 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory corruption in Graphics while importing a file. | ||
| CVE-2023-21642 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory corruption in HAB Memory management due to broad system privileges via physical address. | ||
| CVE-2023-21630 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. | ||
| CVE-2022-40532 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | ||
| CVE-2022-33282 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback. | ||
| CVE-2022-40540 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel. | ||
| CVE-2022-40539 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Automotive Android OS due to improper validation of array index. | ||
| CVE-2022-40531 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. | ||
| CVE-2022-40530 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. | ||
| CVE-2022-25709 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to use of out of range pointer offset while processing qmi msg | ||
| CVE-2022-25694 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | ||
| CVE-2022-25655 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. | ||
| CVE-2022-33277 | Hig | 0.55 | 8.4 | 0.00 | Feb 12, 2023 | Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. | ||
| CVE-2022-33243 | Hig | 0.55 | 8.4 | 0.00 | Feb 12, 2023 | Memory corruption due to improper access control in Qualcomm IPC. | ||
| CVE-2022-40520 | Hig | 0.55 | 8.4 | 0.01 | Jan 9, 2023 | Memory corruption due to stack-based buffer overflow in Core | ||
| CVE-2022-40517 | Hig | 0.55 | 8.4 | 0.00 | Jan 9, 2023 | Memory corruption in core due to stack-based buffer overflow |
- risk 0.55cvss 8.4epss 0.00
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while reading ACPI config through the user mode app.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Multimedia due to improper access control in HAB.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while running VK synchronization with KASAN enabled.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when processing cmd parameters while parsing vdev.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Kernel while parsing metadata.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Display while destroying the image handle created using connected display driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in DSP Service during a remote call from HLOS to DSP.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in HLOS while registering for key provisioning notify.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Graphics while processing user packets for command submission.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper validation of array index in Audio.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory in COmxApeDec module in Audio.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while playing amrwbplus clips with modified content.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while allocating the ion buffer during the music playback.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive GPU while querying a gsl memory node.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
- risk 0.55cvss 8.4epss 0.01
Memory corruption due to double free in Core while mapping HLOS address to the list.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Graphics while importing a file.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HAB Memory management due to broad system privileges via physical address.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Android OS due to improper validation of array index.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper access control in Qualcomm IPC.
- risk 0.55cvss 8.4epss 0.01
Memory corruption due to stack-based buffer overflow in Core
- risk 0.55cvss 8.4epss 0.00
Memory corruption in core due to stack-based buffer overflow
Page 16 of 61