Vulnerabilities > Qualcomm > Sd865 5G Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2023-33064 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Audio when invoking callback function of ASM driver.
local
low complexity
qualcomm CWE-125
5.5
2024-01-02 CVE-2023-33036 NULL Pointer Dereference vulnerability in Qualcomm products
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
local
low complexity
qualcomm CWE-476
5.5
2024-01-02 CVE-2023-33037 Missing Encryption of Sensitive Data vulnerability in Qualcomm products
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
local
low complexity
qualcomm CWE-311
5.5
2023-12-05 CVE-2023-28586 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
local
low complexity
qualcomm CWE-119
6.5
2023-11-07 CVE-2023-28553 Unspecified vulnerability in Qualcomm products
Information Disclosure in WLAN Host when processing WMI event command.
local
low complexity
qualcomm
5.5
2023-11-07 CVE-2023-28554 Unspecified vulnerability in Qualcomm products
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
local
low complexity
qualcomm
5.5
2023-10-03 CVE-2023-28571 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
local
low complexity
qualcomm CWE-125
5.5
2023-09-05 CVE-2022-33220 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Automotive multimedia due to buffer over-read.
local
low complexity
qualcomm CWE-125
5.5
2023-09-05 CVE-2023-21667 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
low complexity
qualcomm CWE-125
6.5
2023-08-08 CVE-2023-21647 Improper Input Validation vulnerability in Qualcomm products
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
network
low complexity
qualcomm CWE-20
6.5