Vulnerabilities > Qualcomm > Wcd9385 Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-09-16 CVE-2022-25693 Use After Free vulnerability in Qualcomm products
Memory corruption in graphics due to use-after-free while graphics profiling in Snapdragon Connectivity, Snapdragon Mobile
local
low complexity
qualcomm CWE-416
7.8
2022-09-16 CVE-2022-25696 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption in display due to time-of-check time-of-use race condition during map or unmap in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
high complexity
qualcomm CWE-367
7.0
2022-09-16 CVE-2022-25706 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
network
low complexity
qualcomm CWE-125
7.5
2022-09-16 CVE-2022-25708 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile
network
low complexity
qualcomm CWE-120
critical
9.8
2022-09-02 CVE-2021-35097 Improper Verification of Cryptographic Signature vulnerability in Qualcomm products
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
low complexity
qualcomm CWE-347
6.8
2022-09-02 CVE-2021-35108 Improper Check for Unusual or Exceptional Conditions vulnerability in Qualcomm products
Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-754
6.8
2022-09-02 CVE-2021-35109 Improper Input Validation vulnerability in Qualcomm products
Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-20
6.8
2022-09-02 CVE-2021-35122 Improper Input Validation vulnerability in Qualcomm products
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
low complexity
qualcomm CWE-20
7.8
2022-09-02 CVE-2021-35132 Improper Validation of Specified Quantity in Input vulnerability in Qualcomm products
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
low complexity
qualcomm CWE-1284
7.8
2022-09-02 CVE-2021-35133 Use After Free vulnerability in Qualcomm products
Use after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-416
6.7