Vulnerabilities > Qualcomm > Wcd9385 Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2023-43518 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in video while parsing invalid mp2 clip.
network
low complexity
qualcomm CWE-787
critical
9.8
2024-02-06 CVE-2023-43519 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
network
low complexity
qualcomm CWE-120
critical
9.8
2024-02-06 CVE-2023-43520 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
network
low complexity
qualcomm CWE-787
critical
9.8
2024-02-06 CVE-2023-43532 Release of Invalid Pointer or Reference vulnerability in Qualcomm products
Memory corruption while reading ACPI config through the user mode app.
local
low complexity
qualcomm CWE-763
7.8
2024-02-06 CVE-2023-43534 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
network
low complexity
qualcomm CWE-119
critical
9.8
2024-02-06 CVE-2023-43535 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
local
low complexity
qualcomm CWE-129
7.8
2024-02-06 CVE-2023-33046 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
local
high complexity
qualcomm CWE-367
7.0
2024-02-06 CVE-2023-33058 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Modem while processing SIB5.
network
low complexity
qualcomm CWE-125
critical
9.1
2024-02-06 CVE-2023-33060 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
local
low complexity
qualcomm CWE-125
5.5
2024-02-06 CVE-2023-33065 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure in Audio while accessing AVCS services from ADSP payload.
local
low complexity
qualcomm CWE-125
7.1