CVE-2023-33042 – Improper Input Validation in Modem
https://notcve.org/view.php?id=CVE-2023-33042
Transient DOS in Modem after RRC Setup message is received. DOS transitorio en el módem después de recibir el mensaje de configuración de RRC. • https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin • CWE-20: Improper Input Validation •
CVE-2023-33018 – Integer Overflow to Buffer Overflow in User Identity Module
https://notcve.org/view.php?id=CVE-2023-33018
Memory corruption while using the UIM diag command to get the operators name. Corrupción de la memoria al utilizar el comando diag de User Identity Module (UIM) para obtener el nombre del operador. • https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin • CWE-190: Integer Overflow or Wraparound CWE-680: Integer Overflow to Buffer Overflow •
CVE-2023-33017 – Buffer Copy Without Checking Size of Input in Boot
https://notcve.org/view.php?id=CVE-2023-33017
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. Corrupción de la memoria en el arranque mientras se ejecuta una prueba ListVars en el menú UEFI durante el arranque. • https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2023-33074 – Use After Free in Audio
https://notcve.org/view.php?id=CVE-2023-33074
Memory corruption in Audio when SSR event is triggered after music playback is stopped. Corrupción de la memoria en Audio cuando se activa el evento SSR después de detener la reproducción de música. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-416: Use After Free CWE-787: Out-of-bounds Write •
CVE-2023-33047 – Buffer Over-read in WLAN Firmware
https://notcve.org/view.php?id=CVE-2023-33047
Transient DOS in WLAN Firmware while parsing no-inherit IES. DOS transitorio en WLAN Firmware mientras se analiza IES sin herencia. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •