Vulnerabilities > Qualcomm

DATE CVE VULNERABILITY TITLE RISK
2024-06-03 CVE-2023-43538 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
local
low complexity
qualcomm CWE-120
7.8
2024-06-03 CVE-2023-43543 Use After Free vulnerability in Qualcomm products
Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.
local
high complexity
qualcomm CWE-416
7.0
2024-06-03 CVE-2023-43544 Use After Free vulnerability in Qualcomm products
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
local
low complexity
qualcomm CWE-416
7.8
2024-06-03 CVE-2023-43545 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption when more scan frequency list or channels are sent from the user space.
local
low complexity
qualcomm CWE-190
7.8
2024-06-03 CVE-2023-43551 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
network
low complexity
qualcomm CWE-287
7.5
2024-06-03 CVE-2023-43555 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Video while parsing mp2 clip with invalid section length.
network
low complexity
qualcomm CWE-125
7.5
2024-06-03 CVE-2023-43556 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in Hypervisor when platform information mentioned is not aligned.
local
low complexity
qualcomm CWE-120
8.8
2024-06-03 CVE-2024-21478 NULL Pointer Dereference vulnerability in Qualcomm products
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
local
low complexity
qualcomm CWE-476
5.5
2024-06-03 CVE-2024-23360 Unspecified vulnerability in Qualcomm products
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
local
low complexity
qualcomm
7.8
2024-05-06 CVE-2023-33119 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
local
high complexity
qualcomm CWE-367
7.0