CVE-2017-18153
Published Nov 26, 2024A race condition exists in a driver potentially leading to a use-after-free condition.
Vendor archive
2,506 CVEs tagged to vendor qualcomm — 535 Critical, 1,518 High, 452 Medium, 1 Low, 0 Unrated.
A race condition exists in a driver potentially leading to a use-after-free condition.
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory acc…
Initial xbl_sec revision does not have all the debug policy features and critical checks.
Possible out of bound access in audio module due to lack of validation of user provided input.
Certain unprivileged processes are able to perform IOCTL calls.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU commands.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
Memory corruption while station LL statistic handling.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Transient DOS while processing the CU information from RNR IE.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption while processing IOCTL calls to unmap the buffers.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Memory corruption while processing the update SIM PB records request.
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.