CVE-2022-33211 – Improper Input Validation in MODEM
https://notcve.org/view.php?id=CVE-2022-33211
memory corruption in modem due to improper check while calculating size of serialized CoAP message • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-20: Improper Input Validation CWE-131: Incorrect Calculation of Buffer Size •
CVE-2022-25747 – Buffer Over-read in MODEM
https://notcve.org/view.php?id=CVE-2022-25747
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •
CVE-2022-25740 – Buffer Copy Without Checking Size of Input in MODEM
https://notcve.org/view.php?id=CVE-2022-25740
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •
CVE-2022-25739 – Null Point Dereference in MODEM
https://notcve.org/view.php?id=CVE-2022-25739
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-476: NULL Pointer Dereference •
CVE-2022-25737 – Use of Uninitialized Variable in MODEM
https://notcve.org/view.php?id=CVE-2022-25737
Information disclosure in modem due to missing NULL check while reading packets received from local network • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-457: Use of Uninitialized Variable CWE-908: Use of Uninitialized Resource •