Vulnerabilities > Qualcomm > Wcn3950 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-05 CVE-2023-28549 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
local
low complexity
qualcomm CWE-119
7.8
2023-09-05 CVE-2023-28557 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
local
low complexity
qualcomm CWE-129
7.8
2023-09-05 CVE-2023-28558 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28559 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28560 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28564 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28565 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28567 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while handling command through WMI interfaces.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28573 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in WLAN HAL while parsing WMI command parameters.
local
low complexity
qualcomm CWE-787
7.8
2023-09-05 CVE-2023-28584 Unspecified vulnerability in Qualcomm products
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
network
low complexity
qualcomm
7.5