Page 3 of 113 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 17EXPL: 0

07 Apr 2025 — Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVSS: 6.7EPSS: 0%CPEs: 4EXPL: 1

07 Apr 2025 — Memory corruption while processing multiple IOCTL calls from HLOS to DSP. A FASTRPC_ATTR_KEEP_MAP logic bug allows fastrpc_internal_munmap_fd to concurrently free in-use mappings leading to a use-after-free condition. • https://packetstorm.news/files/id/190388 • CWE-416: Use After Free •

CVSS: 8.5EPSS: 0%CPEs: 19EXPL: 0

07 Apr 2025 — Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVSS: 6.2EPSS: 0%CPEs: 15EXPL: 0

07 Apr 2025 — Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-1390: Weak Authentication •

CVSS: 7.8EPSS: 0%CPEs: 11EXPL: 0

07 Apr 2025 — Memory corruption while handling file descriptor during listener registration/de-registration. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-416: Use After Free •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

07 Apr 2025 — Cryptographic issues while generating an asymmetric key pair for RKP use cases. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-749: Exposed Dangerous Method or Function •

CVSS: 5.5EPSS: 0%CPEs: 20EXPL: 0

07 Apr 2025 — There may be information disclosure during memory re-allocation in TZ Secure OS. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

07 Apr 2025 — Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-1220: Insufficient Granularity of Access Control •

CVSS: 7.8EPSS: 0%CPEs: 17EXPL: 1

03 Mar 2025 — Memory corruption while calling the NPU driver APIs concurrently. msm_npu has a race condition between npu_host_unload_network and npu_host_exec_network_v2 that leads to memory corruption. • https://packetstorm.news/files/id/189958 • CWE-416: Use After Free •

CVSS: 7.8EPSS: 0%CPEs: 12EXPL: 1

03 Mar 2025 — Transient DOS may occur while processing the country IE. • https://github.com/ladyg00se/CVE-2024-53027-WIP • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •