Vulnerabilities > Qualcomm > Snapdragon XR2 5G Platform Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-06 | CVE-2023-43519 | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. | 9.8 |
2024-02-06 | CVE-2023-33065 | Out-of-bounds Read vulnerability in Qualcomm products Information disclosure in Audio while accessing AVCS services from ADSP payload. | 7.1 |
2024-01-02 | CVE-2023-33030 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption in HLOS while running playready use-case. | 7.8 |
2024-01-02 | CVE-2023-33033 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption in Audio during playback with speaker protection. | 7.8 |
2024-01-02 | CVE-2023-33036 | NULL Pointer Dereference vulnerability in Qualcomm products Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | 5.5 |
2024-01-02 | CVE-2023-33037 | Missing Encryption of Sensitive Data vulnerability in Qualcomm products Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data. | 5.5 |
2024-01-02 | CVE-2023-33038 | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption while receiving a message in Bus Socket Transport Server. | 7.8 |
2024-01-02 | CVE-2023-33094 | Use After Free vulnerability in Qualcomm products Memory corruption while running VK synchronization with KASAN enabled. | 7.8 |
2024-01-02 | CVE-2023-33110 | Race Condition vulnerability in Qualcomm products The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | 7.0 |
2024-01-02 | CVE-2023-33114 | Use After Free vulnerability in Qualcomm products Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. | 7.8 |