Vulnerabilities > Qualcomm > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-07 CVE-2024-23370 Use After Free vulnerability in Qualcomm products
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
local
low complexity
qualcomm CWE-416
6.7
2024-10-07 CVE-2024-23374 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
local
low complexity
qualcomm CWE-787
6.7
2024-10-07 CVE-2024-23375 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption during the network scan request.
local
low complexity
qualcomm CWE-120
6.7
2024-10-07 CVE-2024-23376 Use After Free vulnerability in Qualcomm products
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
local
low complexity
qualcomm CWE-416
6.7
2024-10-07 CVE-2024-23378 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
local
low complexity
qualcomm CWE-120
6.7
2024-10-07 CVE-2024-23379 Double Free vulnerability in Qualcomm products
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
local
low complexity
qualcomm CWE-415
6.7
2024-10-07 CVE-2024-38425 Incorrect Authorization vulnerability in Qualcomm products
Information disclosure while sending implicit broadcast containing APP launch information.
local
low complexity
qualcomm CWE-863
6.1
2024-07-01 CVE-2024-21460 Use of Insufficiently Random Values vulnerability in Qualcomm products
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
local
low complexity
qualcomm CWE-330
6.5
2024-07-01 CVE-2024-21462 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while loading the TA ELF file.
local
low complexity
qualcomm CWE-125
5.5
2024-02-06 CVE-2023-33060 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
local
low complexity
qualcomm CWE-125
5.5