Vulnerabilities > Qualcomm > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-30 CVE-2019-14130 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
local
low complexity
qualcomm CWE-119
4.6
2020-07-30 CVE-2019-14124 Access of Uninitialized Pointer vulnerability in Qualcomm products
Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
local
low complexity
qualcomm CWE-824
4.6
2020-07-30 CVE-2019-14123 Improper Input Validation vulnerability in Qualcomm products
Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
local
low complexity
qualcomm CWE-20
4.6
2020-07-30 CVE-2019-14100 Improper Input Validation vulnerability in Qualcomm products
Register write via debugfs is disabled by default to prevent register writing via debugfs.
local
low complexity
qualcomm CWE-20
4.6
2020-07-30 CVE-2019-14099 Classic Buffer Overflow vulnerability in Qualcomm products
Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, MDM9206, MDM9207C, MDM9607, MSM8909W, MSM8917, MSM8953, Nicobar, QCM2150, QCS405, QCS605, QM215, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
local
low complexity
qualcomm CWE-120
4.6
2020-07-30 CVE-2019-14093 Improper Validation of Array Index vulnerability in Qualcomm products
Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCM2150, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM636, SDM660, SDX20
local
low complexity
qualcomm CWE-129
4.6
2020-07-30 CVE-2019-14037 Use After Free vulnerability in Qualcomm products
Close and bind operations done on a socket can lead to a Use-After-Free condition.
local
low complexity
qualcomm CWE-416
4.6
2020-07-30 CVE-2019-10580 Use After Free vulnerability in Qualcomm products
When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9607, MSM8909W, Nicobar, QCM2150, QCS405, QCS605, Saipan, SC8180X, SDM429W, SDX55, SM8150, SM8250, SXR2130
local
low complexity
qualcomm CWE-416
4.6
2020-06-22 CVE-2020-3676 Improper Validation of Array Index vulnerability in Qualcomm products
Possible memory corruption in perfservice due to improper validation array length taken from user application.
local
low complexity
qualcomm CWE-129
4.6
2020-06-22 CVE-2020-3665 Improper Validation of Array Index vulnerability in Qualcomm products
A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firmware being out of range in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909W, MSM8996, MSM8996AU, QCA6174A, QCA9377, QCA9379, SDM439, SDM636, SDM660, SDX20, SDX24, SM8150
local
low complexity
qualcomm CWE-129
4.6