Vulnerabilities > Qualcomm > Qca0000 Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-33083 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in WLAN Host while processing RRM beacon on the AP.
network
low complexity
qualcomm CWE-120
critical
9.8
2023-12-05 CVE-2023-33082 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
network
low complexity
qualcomm CWE-120
critical
9.8
2023-11-07 CVE-2023-33045 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
network
low complexity
qualcomm CWE-787
critical
9.8
2023-10-03 CVE-2023-33028 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
network
low complexity
qualcomm CWE-787
critical
9.8
2022-10-19 CVE-2022-25718 Unchecked Return Value vulnerability in Qualcomm products
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-252
critical
9.8
2021-06-09 CVE-2020-11159 Out-of-bounds Read vulnerability in Qualcomm products
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-125
critical
9.1
2021-02-22 CVE-2020-11276 Out-of-bounds Read vulnerability in Qualcomm products
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-125
critical
9.1