Vulnerabilities > Qualcomm > Sd888 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-09 CVE-2022-22088 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote
low complexity
qualcomm CWE-787
8.8
2023-01-09 CVE-2022-25746 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
local
low complexity
qualcomm CWE-120
7.8
2023-01-09 CVE-2022-33276 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
local
low complexity
qualcomm CWE-120
7.8
2023-01-09 CVE-2022-40516 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in Core due to stack-based buffer overflow.
local
low complexity
qualcomm CWE-787
7.8
2023-01-09 CVE-2022-40517 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in core due to stack-based buffer overflow
local
low complexity
qualcomm CWE-787
7.8
2023-01-09 CVE-2022-40520 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption due to stack-based buffer overflow in Core
local
low complexity
qualcomm CWE-787
7.8
2022-12-13 CVE-2022-25681 Unspecified vulnerability in Qualcomm products
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caches in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm
7.8
2022-12-13 CVE-2022-25682 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-119
7.8
2022-12-13 CVE-2022-25685 Unspecified vulnerability in Qualcomm products
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
network
low complexity
qualcomm
7.5
2022-12-13 CVE-2022-25695 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-129
7.8