Vulnerabilities > Qualcomm > Qcs8550 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-23377 Unspecified vulnerability in Qualcomm products
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
local
low complexity
qualcomm
6.7
2024-11-04 CVE-2024-23385 Reachable Assertion vulnerability in Qualcomm products
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
network
low complexity
qualcomm CWE-617
6.5
2024-11-04 CVE-2024-33068 Use After Free vulnerability in Qualcomm products
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
network
low complexity
qualcomm CWE-416
6.5
2024-11-04 CVE-2024-38405 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while processing the CU information from RNR IE.
network
low complexity
qualcomm CWE-125
6.5
2024-07-01 CVE-2024-21460 Use of Insufficiently Random Values vulnerability in Qualcomm products
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
local
low complexity
qualcomm CWE-330
6.5
2024-07-01 CVE-2024-21462 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while loading the TA ELF file.
local
low complexity
qualcomm CWE-125
5.5
2024-02-06 CVE-2023-33060 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
local
low complexity
qualcomm CWE-125
5.5
2024-01-02 CVE-2023-33014 Improper Input Validation vulnerability in Qualcomm products
Information disclosure in Core services while processing a Diag command.
low complexity
qualcomm CWE-20
6.8
2024-01-02 CVE-2023-33036 NULL Pointer Dereference vulnerability in Qualcomm products
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
local
low complexity
qualcomm CWE-476
5.5
2024-01-02 CVE-2023-33037 Missing Encryption of Sensitive Data vulnerability in Qualcomm products
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
local
low complexity
qualcomm CWE-311
5.5