CVE-2023-33081
Published Dec 5, 2023Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Vendor/product archive
218 CVEs tagged to qualcomm / qca6390 — 32 Critical, 136 High, 50 Medium, 0 Low, 0 Unrated.
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Memory corruption in Audio while running invalid audio recording from ADSP.
Transient DOS in Data modem while handling TLB control messages from the Network.
Transient DOS in Modem after RRC Setup message is received.
Memory corruption while sending SMS from AP firmware.
Memory corruption in HLOS while invoking IOCTL calls from user-space.
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
Memory corruption while invoking callback function of AFE from ADSP.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
Memory corruption in Audio during playback session with audio effects enabled.
Transient DOS in Modem while processing invalid System Information Block 1.
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
Memory Corruption due to improper validation of array index in Linux while updating adn record.
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
Information disclosure in Automotive multimedia due to buffer over-read.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.