Vulnerabilities > Qualcomm > SD 8 Gen1 5G Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-09-16 CVE-2022-25696 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption in display due to time-of-check time-of-use race condition during map or unmap in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
high complexity
qualcomm CWE-367
7.0
2022-09-16 CVE-2022-25706 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
network
low complexity
qualcomm CWE-125
7.5
2022-09-16 CVE-2022-25708 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile
network
low complexity
qualcomm CWE-120
critical
9.8
2022-09-02 CVE-2021-35108 Improper Check for Unusual or Exceptional Conditions vulnerability in Qualcomm products
Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-754
6.8
2022-09-02 CVE-2021-35109 Improper Input Validation vulnerability in Qualcomm products
Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-20
6.8
2022-09-02 CVE-2021-35133 Use After Free vulnerability in Qualcomm products
Use after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-416
6.7
2022-09-02 CVE-2021-35134 Incorrect Calculation of Buffer Size vulnerability in Qualcomm products
Due to insufficient validation of ELF headers, an Incorrect Calculation of Buffer Size can occur in Boot leading to memory corruption in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-131
8.4
2022-09-02 CVE-2022-22059 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption due to out of bound read while parsing a video file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-125
7.8
2022-09-02 CVE-2022-22061 Unspecified vulnerability in Qualcomm products
Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
local
low complexity
qualcomm
7.8
2022-09-02 CVE-2022-22062 Out-of-bounds Read vulnerability in Qualcomm products
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
network
low complexity
qualcomm CWE-125
critical
9.1