Vulnerabilities > Qualcomm > Wcn3980 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-07 CVE-2024-23370 Use After Free vulnerability in Qualcomm products
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
local
low complexity
qualcomm CWE-416
6.7
2024-10-07 CVE-2024-23374 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
local
low complexity
qualcomm CWE-787
6.7
2024-10-07 CVE-2024-23375 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption during the network scan request.
local
low complexity
qualcomm CWE-120
6.7
2024-10-07 CVE-2024-23376 Use After Free vulnerability in Qualcomm products
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
local
low complexity
qualcomm CWE-416
6.7
2024-07-01 CVE-2024-21462 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while loading the TA ELF file.
local
low complexity
qualcomm CWE-125
5.5
2024-02-06 CVE-2023-33064 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS in Audio when invoking callback function of ASM driver.
local
low complexity
qualcomm CWE-125
5.5
2024-01-02 CVE-2023-33036 NULL Pointer Dereference vulnerability in Qualcomm products
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
local
low complexity
qualcomm CWE-476
5.5
2023-12-05 CVE-2023-28586 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
local
low complexity
qualcomm CWE-119
6.5
2023-12-05 CVE-2023-33070 Improper Authentication vulnerability in Qualcomm products
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
local
low complexity
qualcomm CWE-287
5.5
2023-11-07 CVE-2023-28553 Unspecified vulnerability in Qualcomm products
Information Disclosure in WLAN Host when processing WMI event command.
local
low complexity
qualcomm
5.5