Vulnerabilities > Qualcomm > Qca6391 Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-38418 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while parsing the memory map info in IOCTL calls.
local
high complexity
qualcomm CWE-367
7.0
2025-02-03 CVE-2024-38420 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while configuring a Hypervisor based input virtual device.
local
low complexity
qualcomm CWE-787
7.8
2025-02-03 CVE-2024-45560 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
local
high complexity
qualcomm CWE-367
7.0
2025-02-03 CVE-2024-45561 Use After Free vulnerability in Qualcomm products
Memory corruption while handling IOCTL call from user-space to set latency level.
local
low complexity
qualcomm CWE-416
7.8
2025-02-03 CVE-2024-45584 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
local
low complexity
qualcomm CWE-119
7.8
2025-02-03 CVE-2024-49834 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while power-up or power-down sequence of the camera sensor.
local
low complexity
qualcomm CWE-129
7.8
2025-02-03 CVE-2024-49838 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while parsing the OCI IE with invalid length.
network
low complexity
qualcomm CWE-125
7.5
2025-02-03 CVE-2024-49839 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption during management frame processing due to mismatch in T2LM info element.
network
low complexity
qualcomm CWE-125
critical
9.8
2025-02-03 CVE-2024-49843 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
local
low complexity
qualcomm CWE-129
7.8
2025-01-06 CVE-2024-33067 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
local
low complexity
qualcomm CWE-125
5.5