
CVE-2022-40531 – Incorrect type conversion in WLAN
https://notcve.org/view.php?id=CVE-2022-40531
07 Mar 2023 — Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. • https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletin • CWE-704: Incorrect Type Conversion or Cast •

CVE-2022-25655 – Buffer copy without checking the size of input in WLAN HAL.
https://notcve.org/view.php?id=CVE-2022-25655
07 Mar 2023 — Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. • https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-40512 – Buffer over-read in WLAN Firmware.
https://notcve.org/view.php?id=CVE-2022-40512
09 Feb 2023 — Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. • https://www.qualcomm.com/company/product-security/bulletins/february-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •

CVE-2022-33279 – Stack based buffer overflow in WLAN
https://notcve.org/view.php?id=CVE-2022-33279
09 Feb 2023 — Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length. • https://www.qualcomm.com/company/product-security/bulletins/february-2023-bulletin • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2022-33277 – Buffer copy without checking size of input in modem
https://notcve.org/view.php?id=CVE-2022-33277
09 Feb 2023 — Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. • https://www.qualcomm.com/company/product-security/bulletins/february-2023-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2022-33243 – Improper access control in Qualcomm IPC
https://notcve.org/view.php?id=CVE-2022-33243
09 Feb 2023 — Memory corruption due to improper access control in Qualcomm IPC. • https://www.qualcomm.com/company/product-security/bulletins/february-2023-bulletin • CWE-284: Improper Access Control •

CVE-2022-33286 – Buffer over-read in WLAN
https://notcve.org/view.php?id=CVE-2022-33286
06 Jan 2023 — Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. • https://www.qualcomm.com/company/product-security/bulletins/january-2023-bulletin • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVE-2022-33285 – Buffer over-read in WLAN
https://notcve.org/view.php?id=CVE-2022-33285
06 Jan 2023 — Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. • https://www.qualcomm.com/company/product-security/bulletins/january-2023-bulletin • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVE-2022-25722 – Information Exposure in DSP Services
https://notcve.org/view.php?id=CVE-2022-25722
06 Jan 2023 — Information exposure in DSP services due to improper handling of freeing memory Exposición de información en servicios DSP por manejo inadecuado de liberación de memoria • https://www.qualcomm.com/company/product-security/bulletins/january-2023-bulletin • CWE-416: Use After Free •

CVE-2022-25677
https://notcve.org/view.php?id=CVE-2022-25677
13 Dec 2022 — Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking Corrupción de la memoria en diagnóstico debido al use-after-free mientras se procesa el paquete dci en Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infras... • https://www.qualcomm.com/company/product-security/bulletins/december-2022-bulletin • CWE-416: Use After Free •