Showing 25 vulnerabilities on this page for aqt1000_firmware

Signals CISA KEV Ransomware Nuclei
qualcomm vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Stack-based Buffer Overflow in WLAN Windows Host

Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.

CWE-121CWE-787Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Validation of Array Index in Hypervisor

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

CWE-129Dec 2, 2024
CVSS8.4v3.1EPSS0.104%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Video

Crafted Binder Request Causes Heap UAF in MediaServer

CWE-416Nov 26, 2024
CVSS7.8v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input in Graphics Linux

Memory corruption while processing GPU page table switch.

CWE-120Nov 4, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Integer Overflow to Buffer Overflow in Audio

Memory corruption while processing voice packet with arbitrary data received from ADSP.

CWE-680Nov 4, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cryptographic Issues in BT Controller

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

CWE-310Nov 4, 2024
CVSS8.2v3.1EPSS0.144%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Time-of-check Time-of-use (TOCTOU) Race Condition in Camera

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

CWE-367Nov 4, 2024
CVSS7.8v3.1EPSS0.075%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Time-of-check Time-of-use (TOCTOU) Race Condition in Camera

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

CWE-367Nov 4, 2024
CVSS7.8v3.1EPSS0.075%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Camera

Memory corruption while taking snapshot when an offset variable is set by camera driver.

CWE-20Oct 7, 2024
CVSS8.4v3.1EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in DSP Service

Memory corruption when two threads try to map and unmap a single node simultaneously.

CWE-416Sep 2, 2024
CVSS8.4v3.1EPSS0.166%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM Host

Memory corruption when user provides data for FM HCI command control operations.

CWE-120CWE-787Sep 2, 2024
CVSS7.8v3.1EPSS0.127%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in WLAN Firmware

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

CWE-125CWE-126Sep 2, 2024
CVSS7.5v3.1EPSS0.297%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM Host

Memory corruption when Alternative Frequency offset value is set to 255.

CWE-120CWE-787Sep 2, 2024
CVSS7.8v3.1EPSS0.127%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in Storage

memory corruption when an invalid firehose patch command is invoked.

CWE-119Sep 2, 2024
CVSS6.8v3.1EPSS0.153%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Trusted Execution Environment

Cryptographic issue while parsing RSA keys in COBR format.

CWE-20Sep 2, 2024
CVSS7.1v3.1EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in Multi Mode Call Processor

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

CWE-126Sep 2, 2024
CVSS8.2v3.1EPSS0.264%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Access Control in Graphics Linux

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

CWE-284Aug 5, 2024
CVSS8.4v3.1EPSS0.097%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in WLAN Host

Transient DOS while parsing ESP IE from beacon/probe response frame.

CWE-125CWE-126Aug 5, 2024
CVSS7.5v3.1EPSS0.317%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in HLOS

Memory corruption during session sign renewal request calls in HLOS.

CWE-119CWE-787Aug 5, 2024
CVSS7.8v3.1EPSS0.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in Multi Mode Call Processor

Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

CWE-125CWE-126Aug 5, 2024
CVSS7.5v3.1EPSS0.346%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in Hypervisor

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

CWE-119CWE-787Aug 5, 2024
CVSS8.4v3.1EPSS0.114%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Graphics

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

CWE-416Jul 1, 2024
CVSS8.4v3.1EPSS0.15%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Qualcomm IPC

Memory corruption when allocating and accessing an entry in an SMEM partition.

CWE-120Jul 1, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permissions, Privileges, and Access Control issues in TZ Secure OS

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

CWE-264CWE-787Jul 1, 2024
CVSS7.3v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in Trusted Execution Environment

Memory corruption while processing key blob passed by the user.

CWE-125CWE-126Jul 1, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX