Vulnerabilities > Qualcomm > Qcs404

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2019-2267 Unspecified vulnerability in Qualcomm products
Locked regions may be modified through other interfaces in secure boot loader image due to improper access control.
local
low complexity
qualcomm
7.2
2019-11-21 CVE-2018-13916 Classic Buffer Overflow vulnerability in Qualcomm products
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data.
local
low complexity
qualcomm CWE-120
7.2
2019-07-25 CVE-2019-2346 Improper Validation of Array Index vulnerability in Qualcomm products
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation.
local
low complexity
qualcomm CWE-129
7.2
2019-07-25 CVE-2019-2235 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic.
local
low complexity
qualcomm CWE-119
4.6
2019-07-22 CVE-2018-13927 Improper Authentication vulnerability in Qualcomm products
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SXR1130
local
low complexity
qualcomm CWE-287
7.2
2019-07-22 CVE-2018-13924 Out-of-bounds Write vulnerability in Qualcomm products
Lack of check to prevent the buffer length taking negative values can lead to stack overflow.
network
low complexity
qualcomm CWE-787
critical
10.0
2019-07-22 CVE-2018-13896 Improper Access Control vulnerability in Qualcomm products
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage..
local
low complexity
qualcomm CWE-284
7.2