Vulnerabilities > Qualcomm > Qcs404 Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-05 | CVE-2019-14000 | Out-of-bounds Write vulnerability in Qualcomm products Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption and potential information leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ6018, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCS404, QCS405, QCS605, QM215, Rennell, SA6155P, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130 | 7.8 |
2020-01-21 | CVE-2019-2267 | Unspecified vulnerability in Qualcomm products Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. | 7.8 |
2019-12-12 | CVE-2019-2338 | Unspecified vulnerability in Qualcomm products Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130 | 7.1 |
2019-12-12 | CVE-2019-2321 | Classic Buffer Overflow vulnerability in Qualcomm products Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ4019, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, Snapdragon_High_Med_2016, SXR1130, SXR2130 | 7.8 |
2019-12-12 | CVE-2019-2319 | Out-of-bounds Write vulnerability in Qualcomm products HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130 | 7.8 |
2019-11-21 | CVE-2019-2339 | Improper Validation of Array Index vulnerability in Qualcomm products Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. | 7.8 |
2019-11-21 | CVE-2019-2329 | Use After Free vulnerability in Qualcomm products Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application. | 7.8 |
2019-11-21 | CVE-2019-2315 | Unspecified vulnerability in Qualcomm products While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure environment. | 7.8 |
2019-11-21 | CVE-2018-13916 | Classic Buffer Overflow vulnerability in Qualcomm products Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. | 7.8 |
2019-07-25 | CVE-2019-2346 | Improper Validation of Array Index vulnerability in Qualcomm products Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation. | 7.8 |