Vulnerabilities > Qualcomm > Qca6574Au Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-03 | CVE-2024-49839 | Out-of-bounds Read vulnerability in Qualcomm products Memory corruption during management frame processing due to mismatch in T2LM info element. | 9.8 |
2025-01-06 | CVE-2024-33041 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | 7.8 |
2025-01-06 | CVE-2024-33055 | Use After Free vulnerability in Qualcomm products Memory corruption while invoking IOCTL calls to unmap the DMA buffers. | 7.8 |
2025-01-06 | CVE-2024-33067 | Out-of-bounds Read vulnerability in Qualcomm products Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | 5.5 |
2025-01-06 | CVE-2024-43064 | Allocation of Resources Without Limits or Throttling vulnerability in Qualcomm products Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | 4.7 |
2025-01-06 | CVE-2024-45553 | Use After Free vulnerability in Qualcomm products Memory corruption can occur when process-specific maps are added to the global list. | 7.8 |
2025-01-06 | CVE-2024-45555 | Integer Overflow or Wraparound vulnerability in Qualcomm products Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. | 7.8 |
2025-01-06 | CVE-2024-45558 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | 7.5 |
2024-12-02 | CVE-2024-33036 | Use of Out-of-range Pointer Offset vulnerability in Qualcomm products Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | 6.7 |
2024-12-02 | CVE-2024-33037 | Buffer Over-read vulnerability in Qualcomm products Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. | 6.1 |