Filtered by vendor Qualcomm Subscriptions
Filtered by product Immersive Home 214 Platform Subscriptions
Total 70 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-43523 1 Qualcomm 284 Ar8035, Ar8035 Firmware, Csr8811 and 281 more 2025-06-17 7.5 High
Transient DOS while processing 11AZ RTT management action frame received through OTA.
CVE-2023-33062 1 Qualcomm 580 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 577 more 2025-06-17 7.5 High
Transient DOS in WLAN Firmware while parsing a BTM request.
CVE-2023-33116 1 Qualcomm 204 Ar8035, Ar8035 Firmware, Ar9380 and 201 more 2025-06-17 7.5 High
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
CVE-2023-43511 1 Qualcomm 712 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9206 Lte Modem and 709 more 2025-06-16 7.5 High
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33109 1 Qualcomm 620 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 617 more 2025-06-16 7.5 High
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2023-43513 1 Qualcomm 534 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 531 more 2025-06-16 7.8 High
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
CVE-2022-33275 1 Qualcomm 518 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq5053-aa and 515 more 2025-02-27 8.4 High
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-28544 1 Qualcomm 412 Aqt1000, Aqt1000 Firmware, Ar9380 and 409 more 2025-02-27 7.8 High
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
CVE-2023-28548 1 Qualcomm 366 Aqt1000, Aqt1000 Firmware, Ar8035 and 363 more 2025-02-27 7.8 High
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
CVE-2023-28549 1 Qualcomm 450 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 447 more 2025-02-27 7.8 High
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
CVE-2023-28559 1 Qualcomm 426 Aqt1000, Aqt1000 Firmware, Ar8031 and 423 more 2025-02-27 7.8 High
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
CVE-2023-28560 1 Qualcomm 534 8098, 8098 Firmware, 8998 and 531 more 2025-02-27 7.8 High
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2023-28539 1 Qualcomm 314 Ar8035, Ar8035 Firmware, Ar9380 and 311 more 2025-02-27 6.6 Medium
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
CVE-2023-33028 1 Qualcomm 352 Ar8035, Ar8035 Firmware, Ar9380 and 349 more 2025-02-27 9.8 Critical
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
CVE-2023-33063 1 Qualcomm 595 315 5g Iot Modem, 315 5g Iot Modem Firmware, 8098 and 592 more 2025-01-27 7.8 High
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2024-33056 1 Qualcomm 662 205 Mobile Platform, 205 Mobile Platform Firmware, 315 5g Iot Modem and 659 more 2024-12-12 8.4 High
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2023-33053 1 Qualcomm 234 Csr8811, Csr8811 Firmware, Immersive Home 214 Platform and 231 more 2024-12-02 8.4 High
Memory corruption in Kernel while parsing metadata.
CVE-2023-33083 1 Qualcomm 230 Ar8035, Ar8035 Firmware, Ar9380 and 227 more 2024-12-02 9.8 Critical
Memory corruption in WLAN Host while processing RRM beacon on the AP.
CVE-2024-33012 1 Qualcomm 501 Ar8035, Ar8035 Firmware, Ar9380 and 498 more 2024-11-26 7.5 High
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2024-33013 1 Qualcomm 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more 2024-11-26 7.5 High
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.