Vulnerabilities > Qualcomm > Msm8909W Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-12-02 CVE-2024-43052 Unspecified vulnerability in Qualcomm products
Memory corruption while processing API calls to NPU with invalid input.
local
low complexity
qualcomm
7.8
2024-11-26 CVE-2018-5852 Integer Underflow (Wrap or Wraparound) vulnerability in Qualcomm products
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
local
low complexity
qualcomm CWE-191
7.8
2024-11-26 CVE-2017-11076 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
network
low complexity
qualcomm CWE-119
critical
9.8
2024-11-26 CVE-2018-11952 Improper Authentication vulnerability in Qualcomm products
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
local
low complexity
qualcomm CWE-287
7.8
2024-11-22 CVE-2017-9711 Unspecified vulnerability in Qualcomm products
Certain unprivileged processes are able to perform IOCTL calls.
local
low complexity
qualcomm
7.8
2024-11-04 CVE-2024-38422 Unspecified vulnerability in Qualcomm products
Memory corruption while processing voice packet with arbitrary data received from ADSP.
local
low complexity
qualcomm
7.8
2024-11-04 CVE-2024-38423 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while processing GPU page table switch.
local
low complexity
qualcomm CWE-120
7.8
2024-09-02 CVE-2024-33042 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when Alternative Frequency offset value is set to 255.
local
low complexity
qualcomm CWE-787
7.8
2024-09-02 CVE-2024-33043 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
local
low complexity
qualcomm CWE-125
5.5
2024-09-02 CVE-2024-33052 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when user provides data for FM HCI command control operations.
local
low complexity
qualcomm CWE-787
7.8