Vulnerabilities > Qualcomm > Sa6145P Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2022-33303 Resource Exhaustion vulnerability in Qualcomm products
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
local
low complexity
qualcomm CWE-400
5.5
2023-06-06 CVE-2022-33307 Double Free vulnerability in Qualcomm products
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
local
low complexity
qualcomm CWE-415
7.8
2023-06-06 CVE-2022-40507 Double Free vulnerability in Qualcomm products
Memory corruption due to double free in Core while mapping HLOS address to the list.
local
low complexity
qualcomm CWE-415
7.8
2023-06-06 CVE-2022-40522 Double Free vulnerability in Qualcomm products
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
local
low complexity
qualcomm CWE-415
7.8
2023-06-06 CVE-2022-40523 Exposure of Resource to Wrong Sphere vulnerability in Qualcomm products
Information disclosure in Kernel due to indirect branch misprediction.
local
low complexity
qualcomm CWE-668
5.5
2023-06-06 CVE-2022-40529 Incorrect Authorization vulnerability in Qualcomm products
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
local
low complexity
qualcomm CWE-863
7.8
2023-06-06 CVE-2023-21628 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
local
low complexity
qualcomm CWE-787
7.8
2023-06-06 CVE-2023-21632 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in Automotive GPU while querying a gsl memory node.
local
low complexity
qualcomm CWE-787
7.8
2023-06-06 CVE-2023-21656 Improper Input Validation vulnerability in Qualcomm products
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
local
low complexity
qualcomm CWE-20
7.8
2023-06-06 CVE-2023-21657 Improper Input Validation vulnerability in Qualcomm products
Memoru corruption in Audio when ADSP sends input during record use case.
local
low complexity
qualcomm CWE-20
7.8