Vulnerabilities > Qualcomm > Wcn3980 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-38414 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while processing information on firmware image during core initialization.
local
low complexity
qualcomm CWE-125
5.5
2025-02-03 CVE-2024-38416 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure during audio playback.
local
low complexity
qualcomm CWE-125
5.5
2025-02-03 CVE-2024-38417 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while processing IO control commands.
local
low complexity
qualcomm CWE-125
5.5
2025-01-06 CVE-2024-33061 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
local
low complexity
qualcomm CWE-125
5.5
2025-01-06 CVE-2024-33067 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
local
low complexity
qualcomm CWE-125
5.5
2024-12-02 CVE-2024-33036 Use of Out-of-range Pointer Offset vulnerability in Qualcomm products
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
local
low complexity
qualcomm CWE-823
6.7
2024-12-02 CVE-2024-33037 Buffer Over-read vulnerability in Qualcomm products
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
local
low complexity
qualcomm CWE-126
6.1
2024-12-02 CVE-2024-33039 Untrusted Pointer Dereference vulnerability in Qualcomm products
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
local
low complexity
qualcomm CWE-822
6.7
2024-12-02 CVE-2024-33053 Use After Free vulnerability in Qualcomm products
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
local
low complexity
qualcomm CWE-416
6.7
2024-11-04 CVE-2024-23385 Reachable Assertion vulnerability in Qualcomm products
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
network
low complexity
qualcomm CWE-617
6.5