Vulnerabilities > Qualcomm > Sa6155P Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-05 CVE-2024-33034 Use After Free vulnerability in Qualcomm products
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
local
low complexity
qualcomm CWE-416
7.8
2024-07-01 CVE-2024-21461 Double Free vulnerability in Qualcomm products
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
local
low complexity
qualcomm CWE-415
7.8
2024-07-01 CVE-2024-21465 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption while processing key blob passed by the user.
local
low complexity
qualcomm CWE-125
7.8
2024-07-01 CVE-2024-21469 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
local
low complexity
qualcomm CWE-787
7.8
2024-07-01 CVE-2024-23372 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
local
low complexity
qualcomm CWE-190
7.8
2024-07-01 CVE-2024-23373 Use After Free vulnerability in Qualcomm products
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
local
low complexity
qualcomm CWE-416
7.8
2024-07-01 CVE-2024-23380 Use After Free vulnerability in Qualcomm products
Memory corruption while handling user packets during VBO bind operation.
local
low complexity
qualcomm CWE-416
7.8
2024-06-03 CVE-2023-43538 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
local
low complexity
qualcomm CWE-120
7.8
2024-06-03 CVE-2023-43555 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Video while parsing mp2 clip with invalid section length.
network
low complexity
qualcomm CWE-125
7.5
2024-05-06 CVE-2023-33119 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
local
high complexity
qualcomm CWE-367
7.0