Vulnerabilities > Qualcomm > Wcd9385 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2023-21660 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in WLAN Firmware while parsing FT Information Elements.
network
low complexity
qualcomm CWE-125
7.5
2023-06-06 CVE-2023-21661 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while parsing WLAN beacon or probe-response frame.
network
low complexity
qualcomm CWE-125
7.5
2023-06-06 CVE-2023-21669 Out-of-bounds Read vulnerability in Qualcomm products
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
network
low complexity
qualcomm CWE-125
7.5
2023-06-06 CVE-2023-21670 Incorrect Authorization vulnerability in Qualcomm products
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
local
low complexity
qualcomm CWE-863
7.8
2023-05-02 CVE-2022-40504 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
network
low complexity
qualcomm CWE-617
7.5
2023-05-02 CVE-2022-25713 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
local
low complexity
qualcomm CWE-119
7.8
2023-05-02 CVE-2022-33304 NULL Pointer Dereference vulnerability in Qualcomm products
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
network
low complexity
qualcomm CWE-476
7.5
2023-05-02 CVE-2022-33305 NULL Pointer Dereference vulnerability in Qualcomm products
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
network
low complexity
qualcomm CWE-476
7.5
2023-05-02 CVE-2022-34144 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
network
low complexity
qualcomm CWE-617
7.5
2023-05-02 CVE-2022-40508 Reachable Assertion vulnerability in Qualcomm products
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
network
low complexity
qualcomm CWE-617
7.5