CVE-2023-21642 – Improper Access Control in HAB Memory Management
https://notcve.org/view.php?id=CVE-2023-21642
Memory corruption in HAB Memory management due to broad system privileges via physical address. • https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin • CWE-284: Improper Access Control •
CVE-2022-40508 – Reachable assertion in Modem
https://notcve.org/view.php?id=CVE-2022-40508
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. • https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin • CWE-617: Reachable Assertion •
CVE-2022-40505 – Buffer over-read in Modem
https://notcve.org/view.php?id=CVE-2022-40505
Information disclosure due to buffer over-read in Modem while parsing DNS hostname. • https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •
CVE-2022-34144 – Reachable assertion in Modem
https://notcve.org/view.php?id=CVE-2022-34144
Transient DOS due to reachable assertion in Modem during OSI decode scheduling. • https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin • CWE-617: Reachable Assertion •
CVE-2022-33305 – Null pointer dereference in Modem
https://notcve.org/view.php?id=CVE-2022-33305
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. • https://www.qualcomm.com/company/product-security/bulletins/may-2023-bulletin • CWE-476: NULL Pointer Dereference •