CVE-2023-21647
Published Aug 8, 2023Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Vendor/product archive
148 CVEs tagged to qualcomm / qca6595au_firmware — 8 Critical, 97 High, 43 Medium, 0 Low, 0 Unrated.
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
Information disclosure in DSP Services while loading dynamic module.
Memory corruption in Automotive GPU while querying a gsl memory node.
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
Memory corruption due to use after free in Core when multiple DCI clients register and deregister.
Memory corruption in Audio due to incorrect type cast during audio use-cases.
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host
Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
Memory corruption due to improper validation of array index in Multi-mode call processor.
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file.
Memory corruption in Automotive Android OS due to improper input validation.
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.
Memory corruption in Automotive due to improper input validation.