Qualcomm
Qualcomm Msm8996 Firmware: vulnerabilidades y CVE
Qualcomm Msm8996 Firmware tiene 72 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 28 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE72
Últimos 12 meses0
Críticas28
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11207 | Alta (7.8) | 1.5% | — | 12 nov 2020 | Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052,… |
| CVE-2020-11196 | Crítica (9.8) | 0.90% | — | 12 nov 2020 | u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2020-11193 | Crítica (9.8) | 0.91% | — | 12 nov 2020 | u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2020-11123 | Media (5.5) | 0.19% | — | 12 nov 2020 | u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper… |
| CVE-2020-3644 | Media (5.5) | 0.21% | — | 8 sept 2020 | u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2020-3643 | Media (5.5) | 0.19% | — | 8 sept 2020 | u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2020-3622 | Alta (7.8) | 0.19% | — | 8 sept 2020 | u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon… |
| CVE-2020-3621 | Media (5.5) | 0.22% | — | 8 sept 2020 | u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto,… |
| CVE-2020-3620 | Media (5.5) | 0.19% | — | 8 sept 2020 | u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport can lead to corruption and potential information leak' in Snapdragon Auto, Snapdragon… |
| CVE-2019-14115 | Media (5.5) | 0.21% | — | 8 sept 2020 | u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secure domain as secure… |
| CVE-2019-14074 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon… |
| CVE-2019-13999 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-13998 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-13995 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-13994 | Alta (7.8) | 0.23% | — | 8 sept 2020 | u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than the actual packet size can lead to memory corruption and potential information leakage'… |
| CVE-2019-10615 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of keymaster bob which can lead to memory corruption' in Snapdragon Auto, Snapdragon… |
| CVE-2019-10527 | Alta (7.8) | 0.20% | — | 8 sept 2020 | u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2020-3688 | Crítica (9.8) | 0.88% | — | 30 jul 2020 | Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2019-14101 | Alta (7.1) | 0.19% | — | 30 jul 2020 | Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than expected length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2019-14093 | Alta (7.8) | 0.20% | — | 30 jul 2020 | Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… |
| CVE-2019-14037 | Alta (7.8) | 0.20% | — | 30 jul 2020 | Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… |
| CVE-2020-3665 | Alta (7.8) | 0.22% | — | 22 jun 2020 | A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firmware being out of range in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2020-3663 | Crítica (9.8) | 0.89% | — | 22 jun 2020 | Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2020-3662 | Crítica (9.8) | 0.94% | — | 22 jun 2020 | Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2020-3661 | Crítica (9.8) | 0.88% | — | 22 jun 2020 | Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due to lack of validation checks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2020-3660 | Crítica (9.8) | 0.93% | — | 22 jun 2020 | Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2020-3658 | Crítica (9.1) | 0.92% | — | 22 jun 2020 | Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-14094 | Alta (7.8) | 0.19% | — | 22 jun 2020 | Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2019-14047 | Alta (7.8) | 0.22% | — | 22 jun 2020 | While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit list in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-10597 | Alta (7.8) | 0.20% | — | 22 jun 2020 | kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired… |