Vulnerabilities > Qualcomm > Sdm429W Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-38404 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
network
low complexity
qualcomm CWE-125
7.5
2025-02-03 CVE-2024-38417 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while processing IO control commands.
local
low complexity
qualcomm CWE-125
5.5
2025-02-03 CVE-2024-38418 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while parsing the memory map info in IOCTL calls.
local
high complexity
qualcomm CWE-367
7.0
2025-02-03 CVE-2024-45560 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
local
high complexity
qualcomm CWE-367
7.0
2025-02-03 CVE-2024-45561 Use After Free vulnerability in Qualcomm products
Memory corruption while handling IOCTL call from user-space to set latency level.
local
low complexity
qualcomm CWE-416
7.8
2025-02-03 CVE-2024-45573 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
local
low complexity
qualcomm CWE-119
7.8
2025-02-03 CVE-2024-49832 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
local
low complexity
qualcomm CWE-129
7.8
2025-02-03 CVE-2024-49834 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while power-up or power-down sequence of the camera sensor.
local
low complexity
qualcomm CWE-129
7.8
2025-01-06 CVE-2024-33067 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
local
low complexity
qualcomm CWE-125
5.5
2025-01-06 CVE-2024-43064 Allocation of Resources Without Limits or Throttling vulnerability in Qualcomm products
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
local
high complexity
qualcomm CWE-770
4.7