qualcomm Vulnerabilities and Affected Products
Vulnerabilities associated with c-v2x_9150_firmware.
Products
Clear product- wsa8830_firmware215 vulnerabilities
- wsa8835_firmware215 vulnerabilities
- wcd9380_firmware211 vulnerabilities
- fastconnect_7800_firmware197 vulnerabilities
- fastconnect_6900_firmware194 vulnerabilities
- qca6696_firmware194 vulnerabilities
- wcd9385_firmware190 vulnerabilities
- qca6574au_firmware188 vulnerabilities
- wsa8810_firmware186 vulnerabilities
- wsa8815_firmware184 vulnerabilities
- qca6391_firmware180 vulnerabilities
- qca6574a_firmware175 vulnerabilities
- wcd9370_firmware175 vulnerabilities
- qca6595au_firmware172 vulnerabilities
- qca6698aq_firmware168 vulnerabilities
- qca8081_firmware160 vulnerabilities
- wcd9375_firmware158 vulnerabilities
- wcn3980_firmware157 vulnerabilities
- qca8337_firmware155 vulnerabilities
- sa6155p_firmware154 vulnerabilities
- wcn3988_firmware153 vulnerabilities
- ar8035_firmware150 vulnerabilities
- sa8155p_firmware150 vulnerabilities
- wcd9341_firmware145 vulnerabilities
- fastconnect_6700_firmware142 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-33053MEDIUM | Use After Free in VideoMemory corruption when multiple threads try to unregister the CVP buffer at the same time. CWE-416Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33037MEDIUM | Buffer Over-read in Neural Processing UnitInformation disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. CWE-126Dec 2, 2024 | CVSS6.1v3.1 | EPSS0.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33036MEDIUM | Use of Out-of-range Pointer Offset in Camera DriverMemory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. CWE-823Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38423HIGH | Buffer Copy Without Checking Size of Input in Graphics LinuxMemory corruption while processing GPU page table switch. CWE-120Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38422HIGH | Integer Overflow to Buffer Overflow in AudioMemory corruption while processing voice packet with arbitrary data received from ADSP. CWE-680Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33032MEDIUM | Improper Validation of Array Index in Camera_LinuxMemory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. CWE-129Nov 4, 2024 | CVSS6.7v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38401HIGH | Use After Free in Qualcomm IPCMemory corruption while processing concurrent IOCTL calls. CWE-416Sep 2, 2024 | CVSS7.8v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33060HIGH | Use After Free in DSP ServiceMemory corruption when two threads try to map and unmap a single node simultaneously. CWE-416Sep 2, 2024 | CVSS8.4v3.1 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33016MEDIUM | Improper Restriction of Operations within the Bounds of a Memory Buffer in Storagememory corruption when an invalid firehose patch command is invoked. CWE-119Sep 2, 2024 | CVSS6.8v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33027HIGH | Improper Access Control in Graphics LinuxMemory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. CWE-284Aug 5, 2024 | CVSS8.4v3.1 | EPSS0.097% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23356HIGH | Improper Restriction of Operations within the Bounds of a Memory Buffer in HLOSMemory corruption during session sign renewal request calls in HLOS. | CVSS7.8v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23353HIGH | Buffer Over-read in Multi Mode Call ProcessorTransient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | CVSS7.5v3.1 | EPSS0.346% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23373HIGH | Use After Free in GraphicsMemory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. CWE-416Jul 1, 2024 | CVSS8.4v3.1 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21461HIGH | Double Free in HLOSMemory corruption while performing finish HMAC operation when context is freed by keymaster. CWE-415Jul 1, 2024 | CVSS8.4v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43551CRITICAL | Improper Authentication in Multi-Mode Call ProcessorCryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. CWE-287Jun 3, 2024 | CVSS9.1v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21471HIGH | Use After Free in Graphics LinuxMemory corruption when IOMMU unmap of a GPU buffer fails in Linux. CWE-416May 6, 2024 | CVSS8.4v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43521MEDIUM | Use After Free in HLOSMemory corruption when multiple listeners are being registered with the same file descriptor. CWE-416May 6, 2024 | CVSS6.7v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21468HIGH | Use After Free in KernelMemory corruption when there is failed unmap operation in GPU. CWE-416Apr 1, 2024 | CVSS8.4v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21452HIGH | Improper Input Validation in Automotive TelematicsTransient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions. CWE-20Apr 1, 2024 | CVSS7.3v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33023HIGH | Buffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in SPS-ApplicationsMemory corruption while processing finish_sign command to pass a rsp buffer. CWE-120Apr 1, 2024 | CVSS8.4v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28547HIGH | Buffer Copy Without Checking Size of Input in SPS ApplicationsMemory corruption in SPS Application while requesting for public key in sorter TA. | CVSS8.4v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33066HIGH | Use of Out-of-range Pointer Offset in AudioMemory corruption in Audio while processing RT proxy port register driver. | CVSS8.4v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28578CRITICAL | Improper Input Validation in ServicesMemory corruption in Core Services while executing the command for removing a single event listener. | CVSS9.3v3.1 | EPSS0.124% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33067MEDIUM | Use of Out-of-range Pointer Offset in AudioMemory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. | CVSS6.7v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33065MEDIUM | Buffer Over-read in AudioInformation disclosure in Audio while accessing AVCS services from ADSP payload. | CVSS6.1v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |