Vulnerabilities > Qualcomm > Wcd9385 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-02 CVE-2024-33044 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
local
low complexity
qualcomm CWE-129
7.8
2024-12-02 CVE-2024-33063 Integer Overflow or Wraparound vulnerability in Qualcomm products
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
network
low complexity
qualcomm CWE-190
7.5
2024-12-02 CVE-2024-43048 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
local
low complexity
qualcomm CWE-787
7.8
2024-12-02 CVE-2024-43050 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
local
low complexity
qualcomm CWE-787
7.8
2024-12-02 CVE-2024-43052 Unspecified vulnerability in Qualcomm products
Memory corruption while processing API calls to NPU with invalid input.
local
low complexity
qualcomm
7.8
2024-11-04 CVE-2024-33033 Use After Free vulnerability in Qualcomm products
Memory corruption while processing IOCTL calls to unmap the buffers.
local
low complexity
qualcomm CWE-416
7.8
2024-11-04 CVE-2024-38406 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
local
high complexity
qualcomm CWE-367
7.0
2024-11-04 CVE-2024-38407 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
local
high complexity
qualcomm CWE-367
7.0
2024-11-04 CVE-2024-38409 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while station LL statistic handling.
local
low complexity
qualcomm CWE-120
7.8
2024-11-04 CVE-2024-38410 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
local
low complexity
qualcomm CWE-787
7.8