
CVE-2023-33018 – Integer Overflow to Buffer Overflow in User Identity Module
https://notcve.org/view.php?id=CVE-2023-33018
05 Dec 2023 — Memory corruption while using the UIM diag command to get the operators name. Corrupción de la memoria al utilizar el comando diag de User Identity Module (UIM) para obtener el nombre del operador. • https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin • CWE-190: Integer Overflow or Wraparound CWE-680: Integer Overflow to Buffer Overflow •

CVE-2023-33017 – Buffer Copy Without Checking Size of Input in Boot
https://notcve.org/view.php?id=CVE-2023-33017
05 Dec 2023 — Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. Corrupción de la memoria en el arranque mientras se ejecuta una prueba ListVars en el menú UEFI durante el arranque. • https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-33074 – Use After Free in Audio
https://notcve.org/view.php?id=CVE-2023-33074
07 Nov 2023 — Memory corruption in Audio when SSR event is triggered after music playback is stopped. Corrupción de la memoria en Audio cuando se activa el evento SSR después de detener la reproducción de música. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-416: Use After Free CWE-787: Out-of-bounds Write •

CVE-2023-33059 – Buffer Copy Without Checking Size of Input in Audio
https://notcve.org/view.php?id=CVE-2023-33059
07 Nov 2023 — Memory corruption in Audio while processing the VOC packet data from ADSP. Corrupción de la memoria en Audio mientras se procesan los datos del paquete VOC desde ADSP. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-191: Integer Underflow (Wrap or Wraparound) CWE-787: Out-of-bounds Write •

CVE-2023-33055 – Buffer Copy Without Checking Size of Input in Audio
https://notcve.org/view.php?id=CVE-2023-33055
07 Nov 2023 — Memory Corruption in Audio while invoking callback function in driver from ADSP. Corrupción de la memoria en Audio al invocar la función de devolución de llamada en el controlador desde ADSP. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVE-2023-33047 – Buffer Over-read in WLAN Firmware
https://notcve.org/view.php?id=CVE-2023-33047
07 Nov 2023 — Transient DOS in WLAN Firmware while parsing no-inherit IES. DOS transitorio en WLAN Firmware mientras se analiza IES sin herencia. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •

CVE-2023-33031 – Buffer Copy Without Checking Size of Input in Automotive Audio
https://notcve.org/view.php?id=CVE-2023-33031
07 Nov 2023 — Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. Corrupción de la memoria en Automotive Audio al copiar datos del búfer compartido ADSP al búfer de datos del paquete VOC. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVE-2023-28574 – Improper Input Validation in Core
https://notcve.org/view.php?id=CVE-2023-28574
07 Nov 2023 — Memory corruption in core services when Diag handler receives a command to configure event listeners. Corrupción de la memoria en los servicios principales cuando Diag handler recibe un comando para configurar los detectores de eventos. • https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVE-2023-33035 – Buffer Copy Without Checking Size of Input in Audio
https://notcve.org/view.php?id=CVE-2023-33035
03 Oct 2023 — Memory corruption while invoking callback function of AFE from ADSP. Corrupción de la memoria al invocar la función de devolución de llamada de AFE desde ADSP. • https://www.qualcomm.com/company/product-security/bulletins/october-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-33034 – Signed-to-unsigned conversion error in Audio
https://notcve.org/view.php?id=CVE-2023-33034
03 Oct 2023 — Memory corruption while parsing the ADSP response command. Corrupción de la memoria al analizar el comando de respuesta ADSP. • https://www.qualcomm.com/company/product-security/bulletins/october-2023-bulletin • CWE-195: Signed to Unsigned Conversion Error CWE-787: Out-of-bounds Write •