Qualcomm QCN6224

CPE Details

Qualcomm QCN6224
-
2023-10-03
16h56 +00:00
2023-10-03
16h56 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:h:qualcomm:qcn6224:-:*:*:*:*:*:*:*

Informations

Vendor

qualcomm

Product

qcn6224

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-53027 2025-03-03 10h07 +00:00 Transient DOS may occur while processing the country IE.
7.5
Haute
CVE-2024-53023 2025-03-03 10h07 +00:00 Memory corruption may occur while accessing a variable during extended back to back tests.
7.8
Haute
CVE-2024-53014 2025-03-03 10h07 +00:00 Memory corruption may occur while validating ports and channels in Audio driver.
7.8
Haute
CVE-2024-43051 2025-03-03 10h07 +00:00 Information disclosure while deriving keys for a session for any Widevine use case.
5.5
Moyen
CVE-2024-38426 2025-03-03 10h07 +00:00 While processing the authentication message in UE, improper authentication may lead to information disclosure.
5.4
Moyen
CVE-2024-49839 2025-02-03 16h51 +00:00 Memory corruption during management frame processing due to mismatch in T2LM info element.
9.8
Critique
CVE-2024-49838 2025-02-03 16h51 +00:00 Information disclosure while parsing the OCI IE with invalid length.
8.2
Haute
CVE-2024-45584 2025-02-03 16h51 +00:00 Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
7.8
Haute
CVE-2024-45571 2025-02-03 16h51 +00:00 Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
7.8
Haute
CVE-2024-45569 2025-02-03 16h51 +00:00 Memory corruption while parsing the ML IE due to invalid frame content.
9.8
Critique
CVE-2024-38420 2025-02-03 16h51 +00:00 Memory corruption while configuring a Hypervisor based input virtual device.
8.8
Haute
CVE-2024-38417 2025-02-03 16h51 +00:00 Information disclosure while processing IO control commands.
6.1
Moyen
CVE-2024-38416 2025-02-03 16h51 +00:00 Information disclosure during audio playback.
6.1
Moyen
CVE-2024-38404 2025-02-03 16h51 +00:00 Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
7.5
Haute
CVE-2024-45558 2025-01-06 10h33 +00:00 Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
7.5
Haute
CVE-2024-45553 2025-01-06 10h33 +00:00 Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
7.8
Haute
CVE-2024-33067 2025-01-06 10h33 +00:00 Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
6.1
Moyen
CVE-2024-33063 2024-12-02 10h18 +00:00 Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
7.5
Haute
CVE-2024-33044 2024-12-02 10h18 +00:00 Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
8.4
Haute
CVE-2024-38424 2024-11-04 10h05 +00:00 Memory corruption during GNSS HAL process initialization.
7.8
Haute
CVE-2024-38422 2024-11-04 10h04 +00:00 Memory corruption while processing voice packet with arbitrary data received from ADSP.
7.8
Haute
CVE-2024-38419 2024-11-04 10h04 +00:00 Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
7.8
Haute
CVE-2024-38408 2024-11-04 10h04 +00:00 Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
9.1
Critique
CVE-2024-38405 2024-11-04 10h04 +00:00 Transient DOS while processing the CU information from RNR IE.
7.5
Haute
CVE-2024-38403 2024-11-04 10h04 +00:00 Transient DOS while parsing BTM ML IE when per STA profile is not included.
7.5
Haute
CVE-2024-33068 2024-11-04 10h04 +00:00 Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5
Haute
CVE-2024-33031 2024-11-04 10h04 +00:00 Memory corruption while processing the update SIM PB records request.
6.7
Moyen
CVE-2024-33030 2024-11-04 10h04 +00:00 Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
6.7
Moyen
CVE-2024-23385 2024-11-04 10h04 +00:00 Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
7.5
Haute
CVE-2024-38397 2024-10-07 12h58 +00:00 Transient DOS while parsing probe response and assoc response frame.
7.5
Haute
CVE-2024-33073 2024-10-07 12h58 +00:00 Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
8.2
Haute
CVE-2024-23369 2024-10-07 12h58 +00:00 Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
7.8
Haute
CVE-2024-38402 2024-09-02 10h22 +00:00 Memory corruption while processing IOCTL call for getting group info.
7.8
Haute
CVE-2024-38401 2024-09-02 10h22 +00:00 Memory corruption while processing concurrent IOCTL calls.
7.8
Haute
CVE-2024-33060 2024-09-02 10h22 +00:00 Memory corruption when two threads try to map and unmap a single node simultaneously.
8.4
Haute
CVE-2024-33057 2024-09-02 10h22 +00:00 Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
7.5
Haute
CVE-2024-33051 2024-09-02 10h22 +00:00 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5
Haute
CVE-2024-33050 2024-09-02 10h22 +00:00 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
7.5
Haute
CVE-2024-33048 2024-09-02 10h22 +00:00 Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
7.5
Haute
CVE-2024-33028 2024-08-05 14h21 +00:00 Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
8.4
Haute
CVE-2024-33026 2024-08-05 14h21 +00:00 Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
7.5
Haute
CVE-2024-33024 2024-08-05 14h21 +00:00 Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
7.5
Haute
CVE-2024-33022 2024-08-05 14h21 +00:00 Memory corruption while allocating memory in HGSL driver.
8.4
Haute
CVE-2024-33021 2024-08-05 14h21 +00:00 Memory corruption while processing IOCTL call to set metainfo.
8.4
Haute
CVE-2024-33020 2024-08-05 14h21 +00:00 Transient DOS while processing TID-to-link mapping IE elements.
7.5
Haute
CVE-2024-33019 2024-08-05 14h21 +00:00 Transient DOS while parsing the received TID-to-link mapping action frame.
7.5
Haute
CVE-2024-33018 2024-08-05 14h21 +00:00 Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
7.5
Haute
CVE-2024-33015 2024-08-05 14h21 +00:00 Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
7.5
Haute
CVE-2024-33014 2024-08-05 14h21 +00:00 Transient DOS while parsing ESP IE from beacon/probe response frame.
7.5
Haute
CVE-2024-33013 2024-08-05 14h21 +00:00 Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
7.5
Haute
CVE-2024-33012 2024-08-05 14h21 +00:00 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
7.5
Haute
CVE-2024-33011 2024-08-05 14h21 +00:00 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
7.5
Haute
CVE-2024-33010 2024-08-05 14h21 +00:00 Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5
Haute
CVE-2024-23357 2024-08-05 14h21 +00:00 Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
6.2
Moyen
CVE-2024-23356 2024-08-05 14h21 +00:00 Memory corruption during session sign renewal request calls in HLOS.
7.8
Haute
CVE-2024-23355 2024-08-05 14h21 +00:00 Memory corruption when keymaster operation imports a shared key.
7.8
Haute
CVE-2024-23353 2024-08-05 14h21 +00:00 Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5
Haute
CVE-2024-23352 2024-08-05 14h21 +00:00 Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
7.5
Haute
CVE-2024-23350 2024-08-05 14h21 +00:00 Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
6.5
Moyen
CVE-2024-21481 2024-08-05 14h21 +00:00 Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
8.4
Haute
CVE-2024-21479 2024-08-05 14h21 +00:00 Transient DOS during music playback of ALAC content.
7.5
Haute
CVE-2024-21459 2024-08-05 14h21 +00:00 Information disclosure while handling beacon or probe response frame in STA.
7.5
Haute
CVE-2024-23368 2024-07-01 14h17 +00:00 Memory corruption when allocating and accessing an entry in an SMEM partition.
7.8
Haute
CVE-2024-21469 2024-07-01 14h17 +00:00 Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
7.8
Haute
CVE-2024-21465 2024-07-01 14h17 +00:00 Memory corruption while processing key blob passed by the user.
7.8
Haute
CVE-2024-21462 2024-07-01 14h17 +00:00 Transient DOS while loading the TA ELF file.
7.1
Haute
CVE-2024-21461 2024-07-01 14h17 +00:00 Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4
Haute
CVE-2024-21458 2024-07-01 14h17 +00:00 Information disclosure while handling SA query action frame.
7.5
Haute
CVE-2024-21457 2024-07-01 14h17 +00:00 INformation disclosure while handling Multi-link IE in beacon frame.
7.5
Haute
CVE-2024-21456 2024-07-01 14h17 +00:00 Information Disclosure while parsing beacon frame in STA.
9.1
Critique
CVE-2024-23363 2024-06-03 10h05 +00:00 Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.
7.5
Haute
CVE-2023-43551 2024-06-03 10h05 +00:00 Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
9.1
Critique
CVE-2023-43545 2024-06-03 10h05 +00:00 Memory corruption when more scan frequency list or channels are sent from the user space.
7.8
Haute
CVE-2023-43544 2024-06-03 10h05 +00:00 Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
7.8
Haute
CVE-2023-43542 2024-06-03 10h05 +00:00 Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
7.8
Haute
CVE-2023-43538 2024-06-03 10h05 +00:00 Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
9.3
Critique
CVE-2023-43537 2024-06-03 10h05 +00:00 Information disclosure while handling T2LM Action Frame in WLAN Host.
7.5
Haute
CVE-2024-21480 2024-05-06 14h32 +00:00 Memory corruption while playing audio file having large-sized input buffer.
9.8
Critique
CVE-2024-21477 2024-05-06 14h32 +00:00 Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
7.5
Haute
CVE-2024-21475 2024-05-06 14h32 +00:00 Memory corruption when the payload received from firmware is not as per the expected protocol size.
7.8
Haute
CVE-2023-43531 2024-05-06 14h32 +00:00 Memory corruption while verifying the serialized header when the key pairs are generated.
8.4
Haute
CVE-2023-43530 2024-05-06 14h32 +00:00 Memory corruption in HLOS while checking for the storage type.
7.8
Haute
CVE-2023-43529 2024-05-06 14h32 +00:00 Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
7.5
Haute
CVE-2023-43528 2024-05-06 14h32 +00:00 Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
6.1
Moyen
CVE-2023-43526 2024-05-06 14h32 +00:00 Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
7.8
Haute
CVE-2023-43525 2024-05-06 14h32 +00:00 Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
7.8
Haute
CVE-2023-43524 2024-05-06 14h32 +00:00 Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
7.8
Haute
CVE-2023-43521 2024-05-06 14h32 +00:00 Memory corruption when multiple listeners are being registered with the same file descriptor.
7.8
Haute
CVE-2023-33119 2024-05-06 14h32 +00:00 Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
8.4
Haute
CVE-2024-21473 2024-04-01 15h06 +00:00 Memory corruption while redirecting log file to any file location with any file name.
9.8
Critique
CVE-2024-21463 2024-04-01 15h06 +00:00 Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
9.8
Critique
CVE-2023-33115 2024-04-01 15h05 +00:00 Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
7.8
Haute
CVE-2023-33111 2024-04-01 15h05 +00:00 Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
5.5
Moyen
CVE-2023-33101 2024-04-01 15h05 +00:00 Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
7.5
Haute
CVE-2023-33100 2024-04-01 15h05 +00:00 Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
7.5
Haute
CVE-2023-33099 2024-04-01 15h05 +00:00 Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
7.5
Haute
CVE-2023-33023 2024-04-01 15h05 +00:00 Memory corruption while processing finish_sign command to pass a rsp buffer.
8.4
Haute
CVE-2023-28547 2024-04-01 15h05 +00:00 Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4
Haute
CVE-2023-43553 2024-03-04 10h48 +00:00 Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
9.8
Critique
CVE-2023-43552 2024-03-04 10h48 +00:00 Memory corruption while processing MBSSID beacon containing several subelement IE.
9.8
Critique
CVE-2023-43550 2024-03-04 10h48 +00:00 Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
7.8
Haute
CVE-2023-43549 2024-03-04 10h48 +00:00 Memory corruption while processing TPC target power table in FTM TPC.
8.4
Haute
CVE-2023-43547 2024-03-04 10h48 +00:00 Memory corruption while invoking IOCTLs calls in Automotive Multimedia.
8.4
Haute
CVE-2023-43546 2024-03-04 10h48 +00:00 Memory corruption while invoking HGSL IOCTL context create.
8.4
Haute
CVE-2023-43539 2024-03-04 10h48 +00:00 Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
7.5
Haute
CVE-2023-33105 2024-03-04 10h48 +00:00 Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
7.5
Haute
CVE-2023-33104 2024-03-04 10h48 +00:00 Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
7.5
Haute
CVE-2023-33103 2024-03-04 10h48 +00:00 Transient DOS while processing CAG info IE received from NW.
7.5
Haute
CVE-2023-33096 2024-03-04 10h48 +00:00 Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
7.5
Haute
CVE-2023-33095 2024-03-04 10h48 +00:00 Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
7.5
Haute
CVE-2023-33090 2024-03-04 10h48 +00:00 Transient DOS while processing channel information for speaker protection v2 module in ADSP.
5.5
Moyen
CVE-2023-33086 2024-03-04 10h48 +00:00 Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
7.5
Haute
CVE-2023-33084 2024-03-04 10h48 +00:00 Transient DOS while processing IE fragments from server during DTLS handshake.
7.5
Haute
CVE-2023-33066 2024-03-04 10h48 +00:00 Memory corruption in Audio while processing RT proxy port register driver.
8.4
Haute
CVE-2023-28582 2024-03-04 10h48 +00:00 Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
9.8
Critique
CVE-2023-28578 2024-03-04 10h48 +00:00 Memory corruption in Core Services while executing the command for removing a single event listener.
9.3
Critique
CVE-2023-43536 2024-02-06 05h47 +00:00 Transient DOS while parse fils IE with length equal to 1.
7.5
Haute
CVE-2023-43534 2024-02-06 05h47 +00:00 Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
9.8
Critique
CVE-2023-43533 2024-02-06 05h47 +00:00 Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
7.5
Haute
CVE-2023-43523 2024-02-06 05h47 +00:00 Transient DOS while processing 11AZ RTT management action frame received through OTA.
7.5
Haute
CVE-2023-43522 2024-02-06 05h47 +00:00 Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
7.5
Haute
CVE-2023-43520 2024-02-06 05h47 +00:00 Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
9.8
Critique
CVE-2023-43513 2024-02-06 05h47 +00:00 Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
7.8
Haute
CVE-2023-33077 2024-02-06 05h47 +00:00 Memory corruption in HLOS while converting from authorization token to HIDL vector.
7.8
Haute
CVE-2023-33076 2024-02-06 05h47 +00:00 Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
7.8
Haute
CVE-2023-33072 2024-02-06 05h47 +00:00 Memory corruption in Core while processing control functions.
9.3
Critique
CVE-2023-33069 2024-02-06 05h47 +00:00 Memory corruption in Audio while processing the calibration data returned from ACDB loader.
7.8
Haute
CVE-2023-33068 2024-02-06 05h47 +00:00 Memory corruption in Audio while processing IIR config data from AFE calibration block.
7.8
Haute
CVE-2023-33067 2024-02-06 05h47 +00:00 Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
7.8
Haute
CVE-2023-33065 2024-02-06 05h47 +00:00 Information disclosure in Audio while accessing AVCS services from ADSP payload.
7.1
Haute
CVE-2023-33064 2024-02-06 05h47 +00:00 Transient DOS in Audio when invoking callback function of ASM driver.
5.5
Moyen
CVE-2023-33060 2024-02-06 05h47 +00:00 Transient DOS in Core when DDR memory check is called while DDR is not initialized.
7.1
Haute
CVE-2023-33058 2024-02-06 05h47 +00:00 Information disclosure in Modem while processing SIB5.
9.1
Critique
CVE-2023-33057 2024-02-06 05h47 +00:00 Transient DOS in Multi-Mode Call Processor while processing UE policy container.
7.5
Haute
CVE-2023-33049 2024-02-06 05h46 +00:00 Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
7.5
Haute
CVE-2023-43514 2024-01-02 05h38 +00:00 Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.
8.4
Haute
CVE-2023-43511 2024-01-02 05h38 +00:00 Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
7.5
Haute
CVE-2023-33120 2024-01-02 05h38 +00:00 Memory corruption in Audio when memory map command is executed consecutively in ADSP.
7.8
Haute
CVE-2023-33118 2024-01-02 05h38 +00:00 Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.
7.8
Haute
CVE-2023-33117 2024-01-02 05h38 +00:00 Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.
7.8
Haute
CVE-2023-33116 2024-01-02 05h38 +00:00 Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
7.5
Haute
CVE-2023-33109 2024-01-02 05h38 +00:00 Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
7.5
Haute
CVE-2023-33098 2023-12-05 03h04 +00:00 Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
7.5
Haute
CVE-2023-33097 2023-12-05 03h04 +00:00 Transient DOS in WLAN Firmware while processing a FTMR frame.
7.5
Haute
CVE-2023-33089 2023-12-05 03h04 +00:00 Transient DOS when processing a NULL buffer while parsing WLAN vdev.
7.5
Haute
CVE-2023-33088 2023-12-05 03h04 +00:00 Memory corruption when processing cmd parameters while parsing vdev.
8.4
Haute
CVE-2023-33087 2023-12-05 03h04 +00:00 Memory corruption in Core while processing RX intent request.
7.8
Haute
CVE-2023-33083 2023-12-05 03h04 +00:00 Memory corruption in WLAN Host while processing RRM beacon on the AP.
9.8
Critique
CVE-2023-33082 2023-12-05 03h04 +00:00 Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
9.8
Critique
CVE-2023-33081 2023-12-05 03h04 +00:00 Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
7.5
Haute
CVE-2023-33080 2023-12-05 03h04 +00:00 Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5
Haute
CVE-2023-33079 2023-12-05 03h04 +00:00 Memory corruption in Audio while running invalid audio recording from ADSP.
7.8
Haute
CVE-2023-33054 2023-12-05 03h04 +00:00 Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
9.1
Critique
CVE-2023-33041 2023-12-05 03h04 +00:00 Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
7.5
Haute
CVE-2023-33024 2023-12-05 03h04 +00:00 Memory corruption while sending SMS from AP firmware.
7.8
Haute
CVE-2023-33022 2023-12-05 03h04 +00:00 Memory corruption in HLOS while invoking IOCTL calls from user-space.
8.4
Haute
CVE-2023-33018 2023-12-05 03h04 +00:00 Memory corruption while using the UIM diag command to get the operators name.
7.8
Haute
CVE-2023-33017 2023-12-05 03h03 +00:00 Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
7.8
Haute
CVE-2023-28588 2023-12-05 03h03 +00:00 Transient DOS in Bluetooth Host while rfc slot allocation.
7.5
Haute
CVE-2023-28587 2023-12-05 03h03 +00:00 Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
7.8
Haute
CVE-2023-28586 2023-12-05 03h03 +00:00 Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
6.5
Moyen
CVE-2023-28585 2023-12-05 03h03 +00:00 Memory corruption while loading an ELF segment in TEE Kernel.
8.8
Haute
CVE-2023-28580 2023-12-05 03h03 +00:00 Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
7.8
Haute
CVE-2023-28551 2023-12-05 03h03 +00:00 Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8
Haute
CVE-2023-28550 2023-12-05 03h03 +00:00 Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8
Haute
CVE-2023-28546 2023-12-05 03h03 +00:00 Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8
Haute
CVE-2023-22668 2023-12-05 03h03 +00:00 Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
7.8
Haute
CVE-2023-33061 2023-11-07 05h26 +00:00 Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
7.5
Haute
CVE-2023-33059 2023-11-07 05h26 +00:00 Memory corruption in Audio while processing the VOC packet data from ADSP.
7.8
Haute
CVE-2023-33056 2023-11-07 05h26 +00:00 Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.
7.5
Haute
CVE-2023-33055 2023-11-07 05h26 +00:00 Memory Corruption in Audio while invoking callback function in driver from ADSP.
7.8
Haute
CVE-2023-33048 2023-11-07 05h26 +00:00 Transient DOS in WLAN Firmware while parsing t2lm buffers.
7.5
Haute
CVE-2023-33047 2023-11-07 05h26 +00:00 Transient DOS in WLAN Firmware while parsing no-inherit IES.
7.5
Haute
CVE-2023-33045 2023-11-07 05h26 +00:00 Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
9.8
Critique
CVE-2023-33031 2023-11-07 05h26 +00:00 Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
7.8
Haute
CVE-2023-28574 2023-11-07 05h26 +00:00 Memory corruption in core services when Diag handler receives a command to configure event listeners.
9
Critique
CVE-2023-28570 2023-11-07 05h26 +00:00 Memory corruption while processing audio effects.
7.8
Haute
CVE-2023-28556 2023-11-07 05h26 +00:00 Cryptographic issue in HLOS during key management.
7.8
Haute
CVE-2023-28553 2023-11-07 05h26 +00:00 Information Disclosure in WLAN Host when processing WMI event command.
6.1
Moyen
CVE-2023-28545 2023-11-07 05h26 +00:00 Memory corruption in TZ Secure OS while loading an app ELF.
8.2
Haute
CVE-2023-24852 2023-11-07 05h26 +00:00 Memory Corruption in Core due to secure memory access by user while loading modem image.
8.4
Haute
CVE-2023-22388 2023-11-07 05h26 +00:00 Memory Corruption in Multi-mode Call Processor while processing bit mask API.
9.8
Critique
CVE-2023-33035 2023-10-03 05h00 +00:00 Memory corruption while invoking callback function of AFE from ADSP.
7.8
Haute
CVE-2023-33029 2023-10-03 05h00 +00:00 Memory corruption in DSP Service during a remote call from HLOS to DSP.
8.4
Haute
CVE-2023-33028 2023-10-03 05h00 +00:00 Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
9.8
Critique
CVE-2023-33027 2023-10-03 05h00 +00:00 Transient DOS in WLAN Firmware while parsing rsn ies.
7.5
Haute
CVE-2023-33026 2023-10-03 05h00 +00:00 Transient DOS in WLAN Firmware while parsing a NAN management frame.
7.5
Haute
CVE-2023-28540 2023-10-03 05h00 +00:00 Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
9.1
Critique
CVE-2023-28539 2023-10-03 05h00 +00:00 Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
7.8
Haute
CVE-2023-24855 2023-10-03 05h00 +00:00 Memory corruption in Modem while processing security related configuration before AS Security Exchange.
9.8
Critique
CVE-2023-24853 2023-10-03 05h00 +00:00 Memory Corruption in HLOS while registering for key provisioning notify.
8.4
Haute
CVE-2023-24850 2023-10-03 05h00 +00:00 Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
7.8
Haute
CVE-2023-24849 2023-10-03 05h00 +00:00 Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
8.2
Haute
CVE-2023-24848 2023-10-03 05h00 +00:00 Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
8.2
Haute
CVE-2023-24847 2023-10-03 05h00 +00:00 Transient DOS in Modem while allocating DSM items.
7.5
Haute
CVE-2023-22385 2023-10-03 05h00 +00:00 Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
9.8
Critique
CVE-2023-21673 2023-10-03 05h00 +00:00 Improper Access to the VM resource manager can lead to Memory Corruption.
8.7
Haute