Vulnerabilities > Qualcomm > Qln5040 > High

DATE CVE VULNERABILITY TITLE RISK
2021-02-22 CVE-2020-11287 Information Exposure Through Discrepancy vulnerability in Qualcomm products
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure.
network
low complexity
qualcomm CWE-203
7.5
2021-02-22 CVE-2020-11282 Unspecified vulnerability in Qualcomm products
Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm
7.8
2021-01-21 CVE-2020-3685 Double Free vulnerability in Qualcomm products
Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-415
7.5
2021-01-21 CVE-2020-11217 Double Free vulnerability in Qualcomm products
A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-415
7.8
2021-01-21 CVE-2020-11214 Out-of-bounds Read vulnerability in Qualcomm products
Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it as more number of immutable schedules in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-125
7.5
2021-01-21 CVE-2020-11200 Out-of-bounds Read vulnerability in Qualcomm products
Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side.
network
low complexity
qualcomm CWE-125
7.5
2021-01-21 CVE-2020-11185 Out-of-bounds Write vulnerability in Qualcomm products
Out of bound issue in WLAN driver while processing vdev responses from firmware due to lack of validation of data received from firmware in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-787
7.8
2021-01-21 CVE-2020-11180 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Out of bound access in computer vision control due to improper validation of command length before processing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-119
7.8
2021-01-21 CVE-2020-11179 Out-of-bounds Write vulnerability in Qualcomm products
Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition.
local
high complexity
qualcomm CWE-787
7.0
2021-01-21 CVE-2020-11146 Improper Validation of Array Index vulnerability in Qualcomm products
Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-129
7.8