Vulnerabilities > Qualcomm > Sa8530P Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-38418 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while parsing the memory map info in IOCTL calls.
local
high complexity
qualcomm CWE-367
7.0
2025-02-03 CVE-2024-45569 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while parsing the ML IE due to invalid frame content.
network
low complexity
qualcomm CWE-129
critical
9.8
2025-02-03 CVE-2024-49838 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while parsing the OCI IE with invalid length.
network
low complexity
qualcomm CWE-125
7.5
2025-02-03 CVE-2024-49839 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption during management frame processing due to mismatch in T2LM info element.
network
low complexity
qualcomm CWE-125
critical
9.8
2025-01-06 CVE-2024-33067 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
local
low complexity
qualcomm CWE-125
5.5
2025-01-06 CVE-2024-45558 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
network
low complexity
qualcomm CWE-125
7.5
2024-12-02 CVE-2024-33036 Use of Out-of-range Pointer Offset vulnerability in Qualcomm products
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
local
low complexity
qualcomm CWE-823
6.7
2024-12-02 CVE-2024-33037 Buffer Over-read vulnerability in Qualcomm products
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
local
low complexity
qualcomm CWE-126
6.1
2024-12-02 CVE-2024-33044 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
local
low complexity
qualcomm CWE-129
7.8
2024-12-02 CVE-2024-33053 Use After Free vulnerability in Qualcomm products
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
local
low complexity
qualcomm CWE-416
6.7