Vulnerabilities > Qualcomm > Qcm4490 Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-49833 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption can occur in the camera when an invalid CID is used.
local
low complexity
qualcomm CWE-129
7.8
2025-02-03 CVE-2024-49834 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while power-up or power-down sequence of the camera sensor.
local
low complexity
qualcomm CWE-129
7.8
2025-02-03 CVE-2024-49838 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while parsing the OCI IE with invalid length.
network
low complexity
qualcomm CWE-125
7.5
2025-01-06 CVE-2024-21464 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while processing IPA statistics, when there are no active clients registered.
local
low complexity
qualcomm CWE-120
7.8
2025-01-06 CVE-2024-45553 Use After Free vulnerability in Qualcomm products
Memory corruption can occur when process-specific maps are added to the global list.
local
low complexity
qualcomm CWE-416
7.8
2024-11-04 CVE-2024-23385 Reachable Assertion vulnerability in Qualcomm products
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
network
low complexity
qualcomm CWE-617
6.5
2024-11-04 CVE-2024-38408 Unspecified vulnerability in Qualcomm products
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
network
low complexity
qualcomm
critical
9.1
2024-11-04 CVE-2024-38415 Use After Free vulnerability in Qualcomm products
Memory corruption while handling session errors from firmware.
local
low complexity
qualcomm CWE-416
7.8
2024-11-04 CVE-2024-38424 Use After Free vulnerability in Qualcomm products
Memory corruption during GNSS HAL process initialization.
local
low complexity
qualcomm CWE-416
7.8
2024-09-02 CVE-2024-33038 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
local
low complexity
qualcomm CWE-787
7.8