Vulnerabilities > Qualcomm > Qca6554A Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-04 | CVE-2023-43549 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption while processing TPC target power table in FTM TPC. | 7.8 |
2024-02-06 | CVE-2023-43520 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. | 9.8 |
2024-02-06 | CVE-2023-43534 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | 9.8 |
2024-01-02 | CVE-2023-33113 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. | 7.8 |
2024-01-02 | CVE-2023-43511 | Infinite Loop vulnerability in Qualcomm products Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
2023-12-05 | CVE-2023-28550 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption in MPP performance while accessing DSM watermark using external memory address. | 7.8 |
2023-12-05 | CVE-2023-28587 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. | 7.8 |
2023-12-05 | CVE-2023-33041 | Reachable Assertion vulnerability in Qualcomm products Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids. | 7.5 |
2023-12-05 | CVE-2023-33080 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | 7.5 |
2023-12-05 | CVE-2023-33081 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast. | 7.5 |