qualcomm Vulnerabilities and Affected Products
Vulnerabilities associated with wcd9341_firmware.
Products
Clear product- wsa8830_firmware215 vulnerabilities
- wsa8835_firmware215 vulnerabilities
- wcd9380_firmware211 vulnerabilities
- fastconnect_7800_firmware197 vulnerabilities
- fastconnect_6900_firmware194 vulnerabilities
- qca6696_firmware194 vulnerabilities
- wcd9385_firmware190 vulnerabilities
- qca6574au_firmware188 vulnerabilities
- wsa8810_firmware186 vulnerabilities
- wsa8815_firmware184 vulnerabilities
- qca6391_firmware180 vulnerabilities
- qca6574a_firmware175 vulnerabilities
- wcd9370_firmware175 vulnerabilities
- qca6595au_firmware172 vulnerabilities
- qca6698aq_firmware168 vulnerabilities
- qca8081_firmware160 vulnerabilities
- wcd9375_firmware158 vulnerabilities
- wcn3980_firmware157 vulnerabilities
- qca8337_firmware155 vulnerabilities
- sa6155p_firmware154 vulnerabilities
- wcn3988_firmware153 vulnerabilities
- ar8035_firmware150 vulnerabilities
- sa8155p_firmware150 vulnerabilities
- wcd9341_firmware145 vulnerabilities
- fastconnect_6700_firmware142 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43050HIGH | Stack-based Buffer Overflow in WLAN Windows HostMemory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43048HIGH | Stack-based Buffer Overflow in PerformanceMemory corruption when invalid input is passed to invoke GPU Headroom API call. | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33063HIGH | Integer Overflow or Wraparound in WLAN Host CommunicationTransient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. CWE-190Dec 2, 2024 | CVSS7.5v3.1 | EPSS0.265% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33056HIGH | Buffer Over-read in MProcMemory corruption when allocating and accessing an entry in an SMEM partition continuously. | CVSS8.4v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33053MEDIUM | Use After Free in VideoMemory corruption when multiple threads try to unregister the CVP buffer at the same time. CWE-416Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33044HIGH | Improper Validation of Array Index in HypervisorMemory corruption while Configuring the SMR/S2CR register in Bypass mode. CWE-129Dec 2, 2024 | CVSS8.4v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33037MEDIUM | Buffer Over-read in Neural Processing UnitInformation disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. CWE-126Dec 2, 2024 | CVSS6.1v3.1 | EPSS0.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33036MEDIUM | Use of Out-of-range Pointer Offset in Camera DriverMemory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. CWE-823Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-30299MEDIUM | Improper Input Validation in AudioPossible out of bound access in audio module due to lack of validation of user provided input. CWE-20Nov 22, 2024 | CVSS6.7v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38424HIGH | Use After Free in GPSMemory corruption during GNSS HAL process initialization. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38423HIGH | Buffer Copy Without Checking Size of Input in Graphics LinuxMemory corruption while processing GPU page table switch. CWE-120Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38422HIGH | Integer Overflow to Buffer Overflow in AudioMemory corruption while processing voice packet with arbitrary data received from ADSP. CWE-680Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38419HIGH | Use After Free in Automotive GPUMemory corruption while invoking IOCTL calls from the use-space for HGSL memory node. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38415HIGH | Use After Free in Computer VisionMemory corruption while handling session errors from firmware. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38408HIGH | Cryptographic Issues in BT ControllerCryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. CWE-310Nov 4, 2024 | CVSS8.2v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38407HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in CameraMemory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver. CWE-367Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38406HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in CameraMemory corruption while handling IOCTL calls in JPEG Encoder driver. CWE-367Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33068HIGH | Use After Free in WLAN Host CommunicationTransient DOS while parsing fragments of MBSSID IE from beacon frame. CWE-416Nov 4, 2024 | CVSS7.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33032MEDIUM | Improper Validation of Array Index in Camera_LinuxMemory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. CWE-129Nov 4, 2024 | CVSS6.7v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43047HIGH | Use After Free in DSP ServiceMemory corruption while maintaining memory maps of HLOS memory. CWE-416Oct 7, 2024 | CVSS7.8v3.1 | EPSS0.674% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33065HIGH | Improper Input Validation in CameraMemory corruption while taking snapshot when an offset variable is set by camera driver. CWE-20Oct 7, 2024 | CVSS8.4v3.1 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23379MEDIUM | Double Free in DSP ServicesMemory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario. CWE-415Oct 7, 2024 | CVSS6.7v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38402HIGH | Use After Free in DSP ServicesMemory corruption while processing IOCTL call for getting group info. CWE-416Sep 2, 2024 | CVSS7.8v3.1 | EPSS0.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38401HIGH | Use After Free in Qualcomm IPCMemory corruption while processing concurrent IOCTL calls. CWE-416Sep 2, 2024 | CVSS7.8v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33060HIGH | Use After Free in DSP ServiceMemory corruption when two threads try to map and unmap a single node simultaneously. CWE-416Sep 2, 2024 | CVSS8.4v3.1 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |