Vulnerabilities > Qualcomm > Qcs6125 Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-05 | CVE-2024-33034 | Use After Free vulnerability in Qualcomm products Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | 7.8 |
2024-07-01 | CVE-2024-21461 | Double Free vulnerability in Qualcomm products Memory corruption while performing finish HMAC operation when context is freed by keymaster. | 7.8 |
2024-07-01 | CVE-2024-21465 | Out-of-bounds Read vulnerability in Qualcomm products Memory corruption while processing key blob passed by the user. | 7.8 |
2024-07-01 | CVE-2024-23368 | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption when allocating and accessing an entry in an SMEM partition. | 7.8 |
2024-07-01 | CVE-2024-23372 | Integer Overflow or Wraparound vulnerability in Qualcomm products Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | 7.8 |
2024-07-01 | CVE-2024-23373 | Use After Free vulnerability in Qualcomm products Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | 7.8 |
2024-07-01 | CVE-2024-23380 | Use After Free vulnerability in Qualcomm products Memory corruption while handling user packets during VBO bind operation. | 7.8 |
2024-02-06 | CVE-2023-43513 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | 7.8 |
2024-02-06 | CVE-2023-43533 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | 7.5 |
2024-02-06 | CVE-2023-43536 | Unspecified vulnerability in Qualcomm products Transient DOS while parse fils IE with length equal to 1. | 7.5 |