Page 5 of 257 results (0.004 seconds)

CVSS: 5.5EPSS: 0%CPEs: 804EXPL: 0

17 Mar 2021 — Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking Un uso de syscall por parte de una entidad no segura puede permitir una extracción de información de ... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 738EXPL: 0

17 Mar 2021 — Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una escritura fuera de límite mientras se analiza una cadena SDP debido a una falta de comprobación en una terminación null en los productos Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, ... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 804EXPL: 0

17 Mar 2021 — HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking HLOS para acceder a EL3 stack canary simplemente mapeando la región imem debido a un control inapropiado del acceso y puede conllevar a u... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.1EPSS: 0%CPEs: 804EXPL: 0

17 Mar 2021 — Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una lectura excesiva del búfer puede ocurrir mientras se analizan valores SDP recibidos debido a una falta de comprobación de terminación NULL en SDP en los productos Snapdragon Auto, Snapdragon Compute, Sn... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-125: Out-of-bounds Read •

CVSS: 9.1EPSS: 0%CPEs: 804EXPL: 0

17 Mar 2021 — Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una lectura excesiva del búfer puede pasar mientras se analizan valores SDP recibidos debido a una falta de comprobación de terminación NULL en SDP en los productos Snapdragon Auto, Snapdragon Compute, Snap... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-125: Out-of-bounds Read •

CVSS: 9.1EPSS: 0%CPEs: 798EXPL: 0

17 Mar 2021 — Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una lectura excesiva del búfer puede pasar mientras se analizan unos valores SDP recibidos debido a una falta de comprobación de terminación NULL en SDP en los productos Snapdragon Auto, Snapdragon Compute,... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-125: Out-of-bounds Read •

CVSS: 9.1EPSS: 0%CPEs: 772EXPL: 0

17 Mar 2021 — Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una lectura excesiva del búfer puede ocurrir mientras se analizan valores SDP recibidos debido a una falta de comprobación de terminación NULL en SDP en los productos Snapdragon Auto, Snapdragon Compute, Sn... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-125: Out-of-bounds Read •

CVSS: 9.1EPSS: 0%CPEs: 818EXPL: 0

17 Mar 2021 — Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una posible excepción de lectura fuera de límite cuando UE recibe un número inusualmente grande de octetos de relleno al comienzo del encabezado ROHC en los productos Snapdragon Auto, S... • https://www.qualcomm.com/company/product-security/bulletins/march-2021-bulletin • CWE-125: Out-of-bounds Read •

CVSS: 7.5EPSS: 0%CPEs: 1064EXPL: 0

22 Feb 2021 — Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking Un desbordamiento aritmético puede ocurrir mientras se procesa NOA IE debido a un manejo inapropiado de errores en los productos Snapdragon Auto, Snapdrago... • https://www.qualcomm.com/company/product-security/bulletins/february-2021-bulletin • CWE-617: Reachable Assertion •

CVSS: 6.8EPSS: 0%CPEs: 135EXPL: 0

22 Feb 2021 — An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Se puede producir una Desreferencia del Puntero no Confiable mientras se realizan transferencias de control USB, si múltiples peticiones de diferentes categorías de peticiones están... • https://www.qualcomm.com/company/product-security/bulletins/february-2021-bulletin • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •