Vulnerabilities > Qualcomm > Sd678 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-05 CVE-2023-21662 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in Core Platform while printing the response buffer in log.
local
low complexity
qualcomm CWE-120
7.8
2023-09-05 CVE-2023-21664 Out-of-bounds Write vulnerability in Qualcomm products
Memory Corruption in Core Platform while printing the response buffer in log.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28538 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
local
low complexity
qualcomm CWE-787
7.8
2023-08-08 CVE-2023-21626 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
local
low complexity
qualcomm CWE-287
7.1
2023-08-08 CVE-2023-21651 Incorrect Type Conversion or Cast vulnerability in Qualcomm products
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
local
low complexity
qualcomm CWE-704
7.8
2023-08-08 CVE-2023-21652 Use of Hard-coded Credentials vulnerability in Qualcomm products
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
local
low complexity
qualcomm CWE-798
7.1
2023-08-08 CVE-2023-22666 Out-of-bounds Write vulnerability in Qualcomm products
Memory Corruption in Audio while playing amrwbplus clips with modified content.
local
low complexity
qualcomm CWE-787
7.8
2023-08-08 CVE-2023-28537 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while allocating memory in COmxApeDec module in Audio.
local
low complexity
qualcomm CWE-787
7.8
2023-03-10 CVE-2022-25655 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
local
low complexity
qualcomm CWE-120
7.8
2023-03-10 CVE-2022-25694 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
local
low complexity
qualcomm CWE-119
7.8