
CVE-2022-33302 – Improper validation of array index in User Identity Module
https://notcve.org/view.php?id=CVE-2022-33302
04 Apr 2023 — Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-129: Improper Validation of Array Index •

CVE-2022-33301 – Incorrect type conversion or cast in Audio
https://notcve.org/view.php?id=CVE-2022-33301
04 Apr 2023 — Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-704: Incorrect Type Conversion or Cast •

CVE-2022-33298 – Use after free in Modem
https://notcve.org/view.php?id=CVE-2022-33298
04 Apr 2023 — Memory corruption due to use after free in Modem while modem initialization. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-416: Use After Free •

CVE-2022-33296 – Integer overflow to buffer overflow in Modem
https://notcve.org/view.php?id=CVE-2022-33296
04 Apr 2023 — Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-190: Integer Overflow or Wraparound CWE-680: Integer Overflow to Buffer Overflow •

CVE-2022-33289 – Improper validation of array index in Modem
https://notcve.org/view.php?id=CVE-2022-33289
04 Apr 2023 — Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-129: Improper Validation of Array Index •

CVE-2022-33231 – Double free in Core
https://notcve.org/view.php?id=CVE-2022-33231
04 Apr 2023 — Memory corruption due to double free in core while initializing the encryption key. • https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin • CWE-415: Double Free •

CVE-2022-40540 – Buffer copy without checking the size of input in Linux Kernel
https://notcve.org/view.php?id=CVE-2022-40540
07 Mar 2023 — Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel. • https://bugzilla.suse.com/show_bug.cgi?id=1209597 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-40539 – Improper Validation of Array Index in Automotive Android OS
https://notcve.org/view.php?id=CVE-2022-40539
07 Mar 2023 — Memory corruption in Automotive Android OS due to improper validation of array index. • https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletin • CWE-129: Improper Validation of Array Index CWE-284: Improper Access Control •

CVE-2022-40537 – Improper Validation of Array Index in Bluetooth HOST
https://notcve.org/view.php?id=CVE-2022-40537
07 Mar 2023 — Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. • https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletin • CWE-129: Improper Validation of Array Index •

CVE-2022-40535 – Buffer Over-read in WLAN
https://notcve.org/view.php?id=CVE-2022-40535
07 Mar 2023 — Transient DOS due to buffer over-read in WLAN while sending a packet to device. • https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •