Vulnerabilities > Qualcomm > Qcs6490 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-09-05 CVE-2023-28548 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
local
low complexity
qualcomm CWE-129
7.8
2023-09-05 CVE-2023-28549 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
local
low complexity
qualcomm CWE-119
7.8
2023-09-05 CVE-2023-28557 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
local
low complexity
qualcomm CWE-129
7.8
2023-09-05 CVE-2023-28558 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28567 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while handling command through WMI interfaces.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28573 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while parsing WMI command parameters.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-33015 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
network
low complexity
qualcomm CWE-125
7.5
2023-09-05 CVE-2023-33021 Use After Free vulnerability in Qualcomm products
Memory corruption in Graphics while processing user packets for command submission.
local
low complexity
qualcomm CWE-416
7.8
2023-08-08 CVE-2022-40510 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
network
low complexity
qualcomm CWE-787
critical
9.8
2023-08-08 CVE-2023-21626 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
local
low complexity
qualcomm CWE-287
7.1