qualcomm Vulnerabilities and Affected Products
Vulnerabilities associated with aqt1000_firmware.
Products
Clear product- wsa8830_firmware215 vulnerabilities
- wsa8835_firmware215 vulnerabilities
- wcd9380_firmware211 vulnerabilities
- fastconnect_7800_firmware197 vulnerabilities
- fastconnect_6900_firmware194 vulnerabilities
- qca6696_firmware194 vulnerabilities
- wcd9385_firmware190 vulnerabilities
- qca6574au_firmware188 vulnerabilities
- wsa8810_firmware186 vulnerabilities
- wsa8815_firmware184 vulnerabilities
- qca6391_firmware180 vulnerabilities
- qca6574a_firmware175 vulnerabilities
- wcd9370_firmware175 vulnerabilities
- qca6595au_firmware172 vulnerabilities
- qca6698aq_firmware168 vulnerabilities
- qca8081_firmware160 vulnerabilities
- wcd9375_firmware158 vulnerabilities
- wcn3980_firmware157 vulnerabilities
- qca8337_firmware155 vulnerabilities
- sa6155p_firmware154 vulnerabilities
- wcn3988_firmware153 vulnerabilities
- ar8035_firmware150 vulnerabilities
- sa8155p_firmware150 vulnerabilities
- wcd9341_firmware145 vulnerabilities
- fastconnect_6700_firmware142 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43050HIGH | Stack-based Buffer Overflow in WLAN Windows HostMemory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33044HIGH | Improper Validation of Array Index in HypervisorMemory corruption while Configuring the SMR/S2CR register in Bypass mode. CWE-129Dec 2, 2024 | CVSS8.4v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-11816HIGH | Use After Free in VideoCrafted Binder Request Causes Heap UAF in MediaServer CWE-416Nov 26, 2024 | CVSS7.8v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38423HIGH | Buffer Copy Without Checking Size of Input in Graphics LinuxMemory corruption while processing GPU page table switch. CWE-120Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38422HIGH | Integer Overflow to Buffer Overflow in AudioMemory corruption while processing voice packet with arbitrary data received from ADSP. CWE-680Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38408HIGH | Cryptographic Issues in BT ControllerCryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. CWE-310Nov 4, 2024 | CVSS8.2v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38407HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in CameraMemory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver. CWE-367Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38406HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in CameraMemory corruption while handling IOCTL calls in JPEG Encoder driver. CWE-367Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33065HIGH | Improper Input Validation in CameraMemory corruption while taking snapshot when an offset variable is set by camera driver. CWE-20Oct 7, 2024 | CVSS8.4v3.1 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33060HIGH | Use After Free in DSP ServiceMemory corruption when two threads try to map and unmap a single node simultaneously. CWE-416Sep 2, 2024 | CVSS8.4v3.1 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33052HIGH | Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostMemory corruption when user provides data for FM HCI command control operations. | CVSS7.8v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33051HIGH | Buffer Over-read in WLAN FirmwareTransient DOS while processing TIM IE from beacon frame as there is no check for IE length. | CVSS7.5v3.1 | EPSS0.297% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33042HIGH | Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostMemory corruption when Alternative Frequency offset value is set to 255. | CVSS7.8v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33016MEDIUM | Improper Restriction of Operations within the Bounds of a Memory Buffer in Storagememory corruption when an invalid firehose patch command is invoked. CWE-119Sep 2, 2024 | CVSS6.8v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23362HIGH | Improper Input Validation in Trusted Execution EnvironmentCryptographic issue while parsing RSA keys in COBR format. CWE-20Sep 2, 2024 | CVSS7.1v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23359HIGH | Buffer Over-read in Multi Mode Call ProcessorInformation disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. CWE-126Sep 2, 2024 | CVSS8.2v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33027HIGH | Improper Access Control in Graphics LinuxMemory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. CWE-284Aug 5, 2024 | CVSS8.4v3.1 | EPSS0.097% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33014HIGH | Buffer Over-read in WLAN HostTransient DOS while parsing ESP IE from beacon/probe response frame. | CVSS7.5v3.1 | EPSS0.317% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23356HIGH | Improper Restriction of Operations within the Bounds of a Memory Buffer in HLOSMemory corruption during session sign renewal request calls in HLOS. | CVSS7.8v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23353HIGH | Buffer Over-read in Multi Mode Call ProcessorTransient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | CVSS7.5v3.1 | EPSS0.346% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21481HIGH | Improper Restriction of Operations within the Bounds of a Memory Buffer in HypervisorMemory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | CVSS8.4v3.1 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23373HIGH | Use After Free in GraphicsMemory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. CWE-416Jul 1, 2024 | CVSS8.4v3.1 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23368HIGH | Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Qualcomm IPCMemory corruption when allocating and accessing an entry in an SMEM partition. CWE-120Jul 1, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21469HIGH | Permissions, Privileges, and Access Control issues in TZ Secure OSMemory corruption when an invoke call and a TEE call are bound for the same trusted application. | CVSS7.3v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21465HIGH | Buffer Over-read in Trusted Execution EnvironmentMemory corruption while processing key blob passed by the user. | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |