Vulnerabilities > Qualcomm > Sd888 5G Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-21652 Use of Hard-coded Credentials vulnerability in Qualcomm products
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
local
low complexity
qualcomm CWE-798
7.1
2023-08-08 CVE-2023-22666 Out-of-bounds Write vulnerability in Qualcomm products
Memory Corruption in Audio while playing amrwbplus clips with modified content.
local
low complexity
qualcomm CWE-787
7.8
2023-03-10 CVE-2022-22075 Unspecified vulnerability in Qualcomm products
Information Disclosure in Graphics during GPU context switch.
local
low complexity
qualcomm
5.5
2023-03-10 CVE-2022-25694 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
local
low complexity
qualcomm CWE-119
7.8
2023-03-10 CVE-2022-25705 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
local
low complexity
qualcomm CWE-190
7.8
2023-03-10 CVE-2022-33213 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in modem due to buffer overflow while processing a PPP packet
network
low complexity
qualcomm CWE-120
8.8
2023-03-10 CVE-2022-33242 Improper Authentication vulnerability in Qualcomm products
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
local
low complexity
qualcomm CWE-287
7.8
2023-03-10 CVE-2022-33244 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
network
low complexity
qualcomm CWE-617
7.5
2023-03-10 CVE-2022-33250 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
network
low complexity
qualcomm CWE-617
7.5
2023-03-10 CVE-2022-33254 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
network
low complexity
qualcomm CWE-617
7.5