CVE-2024-33015 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33015
05 Aug 2024 — Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-33014 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33014
05 Aug 2024 — Transient DOS while parsing ESP IE from beacon/probe response frame. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-33013 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33013
05 Aug 2024 — Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-33012 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33012
05 Aug 2024 — Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-33011 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33011
05 Aug 2024 — Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-33010 – Use After Free in WLAN Host
https://notcve.org/view.php?id=CVE-2024-33010
05 Aug 2024 — Transient DOS while parsing fragments of MBSSID IE from beacon frame. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-416: Use After Free •
CVE-2024-23357 – NULL Pointer Dereference in HLOS
https://notcve.org/view.php?id=CVE-2024-23357
05 Aug 2024 — Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-476: NULL Pointer Dereference •
CVE-2024-23353 – Buffer Over-read in Multi Mode Call Processor
https://notcve.org/view.php?id=CVE-2024-23353
05 Aug 2024 — Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-126: Buffer Over-read •
CVE-2024-23352 – Loop with Unreachable Exit Condition (`Infinite Loop`) in Multi Mode Call Processor
https://notcve.org/view.php?id=CVE-2024-23352
05 Aug 2024 — Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •
CVE-2024-23350 – Reachable Assertion in Multi Mode Call Processor
https://notcve.org/view.php?id=CVE-2024-23350
05 Aug 2024 — Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html • CWE-617: Reachable Assertion •