Showing 25 vulnerabilities on this page for ar8031_firmware

Signals CISA KEV Ransomware Nuclei
qualcomm vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Improper Input Validation in Audio

Possible out of bound access in audio module due to lack of validation of user provided input.

CWE-20Nov 22, 2024
CVSS6.7v3.1EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input in Graphics Linux

Memory corruption while processing GPU page table switch.

CWE-120Nov 4, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Integer Overflow to Buffer Overflow in Audio

Memory corruption while processing voice packet with arbitrary data received from ADSP.

CWE-680Nov 4, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in DSP Service

Memory corruption when two threads try to map and unmap a single node simultaneously.

CWE-416Sep 2, 2024
CVSS8.4v3.1EPSS0.166%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in WLAN Firmware

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

CWE-125CWE-126Sep 2, 2024
CVSS7.5v3.1EPSS0.297%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in Storage

memory corruption when an invalid firehose patch command is invoked.

CWE-119Sep 2, 2024
CVSS6.8v3.1EPSS0.153%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Trusted Execution Environment

Cryptographic issue while parsing RSA keys in COBR format.

CWE-20Sep 2, 2024
CVSS7.1v3.1EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Access Control in Graphics Linux

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

CWE-284Aug 5, 2024
CVSS8.4v3.1EPSS0.097%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in WLAN Host

Transient DOS while parsing ESP IE from beacon/probe response frame.

CWE-125CWE-126Aug 5, 2024
CVSS7.5v3.1EPSS0.317%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in HLOS

Memory corruption during session sign renewal request calls in HLOS.

CWE-119CWE-787Aug 5, 2024
CVSS7.8v3.1EPSS0.11%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Graphics

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

CWE-416Jul 1, 2024
CVSS8.4v3.1EPSS0.15%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permissions, Privileges, and Access Control issues in TZ Secure OS

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

CWE-264CWE-787Jul 1, 2024
CVSS7.3v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in Trusted Execution Environment

Memory corruption while processing key blob passed by the user.

CWE-125CWE-126Jul 1, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Double Free in HLOS

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

CWE-415Jul 1, 2024
CVSS8.4v3.1EPSS0.104%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input in Trusted Execution Environment

Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.

CWE-120Jun 3, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Kernel

Memory corruption when there is failed unmap operation in GPU.

CWE-416Apr 1, 2024
CVSS8.4v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in SPS-Applications

Memory corruption while processing finish_sign command to pass a rsp buffer.

CWE-120Apr 1, 2024
CVSS8.4v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Copy Without Checking Size of Input in SPS Applications

Memory corruption in SPS Application while requesting for public key in sorter TA.

CWE-120CWE-787Apr 1, 2024
CVSS8.4v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use of Out-of-range Pointer Offset in Audio

Memory corruption in Audio while processing RT proxy port register driver.

CWE-787CWE-823Mar 4, 2024
CVSS8.4v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Services

Memory corruption in Core Services while executing the command for removing a single event listener.

CWE-20CWE-787Mar 4, 2024
CVSS9.3v3.1EPSS0.124%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Integer Overflow or Wraparound in Graphics Linux

Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

CWE-190Dec 5, 2023
CVSS8.4v3.1EPSS0.892%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in DSP Services

Memory corruption in DSP Services during a remote call from HLOS to DSP.

CWE-416Dec 5, 2023
CVSS7.8v3.1EPSS0.7%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in WLAN Firmware

Transient DOS in WLAN Firmware while parsing rsn ies.

CWE-125CWE-126Oct 3, 2023
CVSS7.5v3.1EPSS0.324%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

NULL pointer Dereference in Modem

Transient DOS in Modem while allocating DSM items.

CWE-476Oct 3, 2023
CVSS7.5v3.1EPSS0.324%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Authorization in WLAN Host

Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.

CWE-285Sep 5, 2023
CVSS7.5v3.1EPSS0.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX