Vulnerabilities > Qualcomm > Msm8996Au Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-07-01 CVE-2024-21461 Double Free vulnerability in Qualcomm products
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
local
low complexity
qualcomm CWE-415
7.8
2024-07-01 CVE-2024-23373 Use After Free vulnerability in Qualcomm products
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
local
low complexity
qualcomm CWE-416
7.8
2024-06-03 CVE-2023-43551 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
network
low complexity
qualcomm CWE-287
7.5
2024-06-03 CVE-2023-43555 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Video while parsing mp2 clip with invalid section length.
network
low complexity
qualcomm CWE-125
7.5
2024-05-06 CVE-2023-43528 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
local
low complexity
qualcomm CWE-125
5.5
2024-04-01 CVE-2023-28547 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in SPS Application while requesting for public key in sorter TA.
local
low complexity
qualcomm CWE-787
7.8
2024-04-01 CVE-2023-33023 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while processing finish_sign command to pass a rsp buffer.
local
low complexity
qualcomm CWE-120
7.8
2024-04-01 CVE-2024-21468 Use After Free vulnerability in Qualcomm products
Memory corruption when there is failed unmap operation in GPU.
local
low complexity
qualcomm CWE-416
7.8
2024-03-04 CVE-2023-33066 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in Audio while processing RT proxy port register driver.
local
low complexity
qualcomm CWE-787
7.8
2024-02-06 CVE-2023-33067 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
local
low complexity
qualcomm CWE-787
7.8