Vulnerabilities > Qualcomm > Snapdragon XR2 5G Platform Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-04 CVE-2024-38415 Use After Free vulnerability in Qualcomm products
Memory corruption while handling session errors from firmware.
local
low complexity
qualcomm CWE-416
7.8
2024-11-04 CVE-2024-38422 Unspecified vulnerability in Qualcomm products
Memory corruption while processing voice packet with arbitrary data received from ADSP.
local
low complexity
qualcomm
7.8
2024-11-04 CVE-2024-38423 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while processing GPU page table switch.
local
low complexity
qualcomm CWE-120
7.8
2024-10-07 CVE-2024-23369 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
local
low complexity
qualcomm CWE-119
7.8
2024-08-05 CVE-2024-33014 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while parsing ESP IE from beacon/probe response frame.
network
low complexity
qualcomm CWE-125
7.5
2024-08-05 CVE-2024-33020 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while processing TID-to-link mapping IE elements.
network
low complexity
qualcomm CWE-125
7.5
2024-08-05 CVE-2024-33023 Use After Free vulnerability in Qualcomm products
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
local
low complexity
qualcomm CWE-416
7.8
2024-08-05 CVE-2024-33024 Integer Overflow or Wraparound vulnerability in Qualcomm products
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
network
low complexity
qualcomm CWE-190
7.5
2024-08-05 CVE-2024-33025 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
network
low complexity
qualcomm CWE-125
7.5
2024-07-01 CVE-2024-21461 Double Free vulnerability in Qualcomm products
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
local
low complexity
qualcomm CWE-415
7.8