Filtered by vendor Qualcomm Subscriptions
Filtered by product Wsa8840 Subscriptions
Total 294 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-33056 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Csr8811 and 229 more 2024-11-21 7.5 High
Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.
CVE-2023-33048 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Csr8811 and 229 more 2024-11-21 7.5 High
Transient DOS in WLAN Firmware while parsing t2lm buffers.
CVE-2023-33045 1 Qualcomm 265 Ar8035, Ar8035 Firmware, Csr8811 and 262 more 2024-11-21 9.8 Critical
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
CVE-2023-33041 1 Qualcomm 254 Ar8035, Ar8035 Firmware, Csr8811 and 251 more 2024-11-21 7.5 High
Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
CVE-2023-28574 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Qam8255p and 153 more 2024-11-21 9 Critical
Memory corruption in core services when Diag handler receives a command to configure event listeners.
CVE-2024-33014 1 Qualcomm 653 315 5g Iot Modem, 315 5g Iot Modem Firmware, 860 Mobile Platform and 650 more 2024-11-20 7.5 High
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33015 1 Qualcomm 393 Ar8035, Ar8035 Firmware, Csr8811 and 390 more 2024-11-20 7.5 High
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVE-2024-33025 1 Qualcomm 340 Csr8811, Csr8811 Firmware, Fastconnect 6800 and 337 more 2024-11-20 7.5 High
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33024 1 Qualcomm 364 Ar8035, Ar8035 Firmware, Csr8811 and 361 more 2024-11-20 7.5 High
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
CVE-2024-33018 1 Qualcomm 303 Ar8035, Ar8035 Firmware, Csr8811 and 300 more 2024-11-20 7.5 High
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
CVE-2024-33026 1 Qualcomm 332 Ar8035, Ar8035 Firmware, Csr8811 and 329 more 2024-11-20 7.5 High
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-33023 1 Qualcomm 317 Ar8035, Ar8035 Firmware, Csra6620 and 314 more 2024-11-20 8.4 High
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
CVE-2024-33022 1 Qualcomm 251 Ar8035, Ar8035 Firmware, Csra6620 and 248 more 2024-11-20 8.4 High
Memory corruption while allocating memory in HGSL driver.
CVE-2024-33021 1 Qualcomm 279 Ar8035, Ar8035 Firmware, Csra6620 and 276 more 2024-11-20 8.4 High
Memory corruption while processing IOCTL call to set metainfo.
CVE-2024-33020 1 Qualcomm 198 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 195 more 2024-11-20 7.5 High
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33019 1 Qualcomm 299 Ar8035, Ar8035 Firmware, Csr8811 and 296 more 2024-11-20 7.5 High
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-33028 1 Qualcomm 279 Ar8035, Ar8035 Firmware, Csra6620 and 276 more 2024-11-20 8.4 High
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
CVE-2024-33034 1 Qualcomm 213 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 210 more 2024-11-20 8.4 High
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
CVE-2024-38424 1 Qualcomm 240 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 237 more 2024-11-16 7.8 High
Memory corruption during GNSS HAL process initialization.
CVE-2024-38410 1 Qualcomm 51 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 48 more 2024-11-16 7.8 High
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.