CVE-2024-33029
Published Nov 4, 2024Memory corruption while handling the PDR in driver for getting the remote heap maps.
Vendor archive
2,506 CVEs tagged to vendor qualcomm — 535 Critical, 1,518 High, 452 Medium, 1 Low, 0 Unrated.
Memory corruption while handling the PDR in driver for getting the remote heap maps.
memory corruption when WiFi display APIs are invoked with large random inputs.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the…
Memory corruption while maintaining memory maps of HLOS memory.
Information disclosure while sending implicit broadcast containing APP launch information.
Memory corruption while processing user packets to generate page faults.
Transient DOS while parsing probe response and assoc response frame.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption while taking snapshot when an offset variable is set by camera driver.
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
Memory corruption during the network scan request.
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Memory corruption while processing IOCTL call for getting group info.