Vulnerabilities > Qualcomm > Qpa4340 > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-22 | CVE-2020-11287 | Unspecified vulnerability in Qualcomm products Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. | 5.0 |
2021-02-22 | CVE-2020-11286 | NULL Pointer Dereference vulnerability in Qualcomm products An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. | 4.6 |
2021-02-22 | CVE-2020-11282 | Incorrect Authorization vulnerability in Qualcomm products Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 4.6 |
2021-01-21 | CVE-2020-11217 | Double Free vulnerability in Qualcomm products A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | 4.6 |
2021-01-21 | CVE-2020-11215 | Out-of-bounds Read vulnerability in Qualcomm products An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 6.4 |
2021-01-21 | CVE-2020-11214 | Out-of-bounds Read vulnerability in Qualcomm products Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it as more number of immutable schedules in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 5.0 |
2021-01-21 | CVE-2020-11200 | Out-of-bounds Read vulnerability in Qualcomm products Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. | 5.0 |
2021-01-21 | CVE-2020-11179 | Out-of-bounds Read vulnerability in Qualcomm products Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition. | 6.9 |
2021-01-21 | CVE-2020-11152 | Race Condition vulnerability in Qualcomm products Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 6.9 |
2021-01-21 | CVE-2020-11145 | Divide By Zero vulnerability in Qualcomm products Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 5.0 |