Vulnerabilities > Qualcomm > Ssg2125P Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-02 | CVE-2024-33048 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | 7.5 |
2024-09-02 | CVE-2024-33050 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | 7.5 |
2024-09-02 | CVE-2024-33051 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | 7.5 |
2024-09-02 | CVE-2024-33057 | Out-of-bounds Read vulnerability in Qualcomm products Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. | 7.5 |
2024-09-02 | CVE-2024-33060 | Use After Free vulnerability in Qualcomm products Memory corruption when two threads try to map and unmap a single node simultaneously. | 7.8 |
2024-09-02 | CVE-2024-38402 | Use After Free vulnerability in Qualcomm products Memory corruption while processing IOCTL call for getting group info. | 7.8 |
2024-08-05 | CVE-2024-23382 | Use After Free vulnerability in Qualcomm products Memory corruption while processing graphics kernel driver request to create DMA fence. | 7.8 |
2024-08-05 | CVE-2024-33023 | Use After Free vulnerability in Qualcomm products Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | 7.8 |
2024-08-05 | CVE-2024-33034 | Use After Free vulnerability in Qualcomm products Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | 7.8 |
2024-07-01 | CVE-2024-21461 | Double Free vulnerability in Qualcomm products Memory corruption while performing finish HMAC operation when context is freed by keymaster. | 7.8 |