Vulnerabilities > Qualcomm > Qcn9024 Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-45569 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while parsing the ML IE due to invalid frame content.
network
low complexity
qualcomm CWE-129
critical
9.8
2025-02-03 CVE-2024-45571 Use After Free vulnerability in Qualcomm products
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
local
low complexity
qualcomm CWE-416
7.8
2025-02-03 CVE-2024-49838 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while parsing the OCI IE with invalid length.
network
low complexity
qualcomm CWE-125
7.5
2025-02-03 CVE-2024-49839 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption during management frame processing due to mismatch in T2LM info element.
network
low complexity
qualcomm CWE-125
critical
9.8
2025-01-06 CVE-2024-45558 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
network
low complexity
qualcomm CWE-125
7.5
2024-12-02 CVE-2024-33063 Integer Overflow or Wraparound vulnerability in Qualcomm products
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
network
low complexity
qualcomm CWE-190
7.5
2024-11-04 CVE-2024-23385 Reachable Assertion vulnerability in Qualcomm products
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
network
low complexity
qualcomm CWE-617
6.5
2024-11-04 CVE-2024-33068 Use After Free vulnerability in Qualcomm products
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
network
low complexity
qualcomm CWE-416
6.5
2024-11-04 CVE-2024-38408 Unspecified vulnerability in Qualcomm products
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
network
low complexity
qualcomm
critical
9.1
2024-11-04 CVE-2024-38415 Use After Free vulnerability in Qualcomm products
Memory corruption while handling session errors from firmware.
local
low complexity
qualcomm CWE-416
7.8