Vulnerabilities (CVE)

Filtered by CWE-126
Total 385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43533 1 Qualcomm 476 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 473 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-28541 1 Qualcomm 398 Aqt1000, Aqt1000 Firmware, Ar8031 and 395 more 2025-08-11 N/A 7.8 HIGH
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
CVE-2023-43528 1 Qualcomm 182 Ar8035, Ar8035 Firmware, C-v2x 9150 and 179 more 2025-08-11 N/A 6.1 MEDIUM
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
CVE-2024-33057 1 Qualcomm 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-43056 1 Qualcomm 384 Aqt1000, Aqt1000 Firmware, Ar8035 and 381 more 2025-08-11 N/A 5.5 MEDIUM
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2023-28571 1 Qualcomm 172 8098, 8098 Firmware, 8998 and 169 more 2025-08-11 N/A 6.1 MEDIUM
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
CVE-2024-33073 1 Qualcomm 318 Ar8035, Ar8035 Firmware, Csr8811 and 315 more 2025-08-11 N/A 8.2 HIGH
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2025-21454 1 Qualcomm 384 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9206 Lte Modem and 381 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while processing received beacon frame.
CVE-2024-38397 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 229 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame.
CVE-2023-24849 1 Qualcomm 476 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9206 Lte Modem and 473 more 2025-08-11 N/A 8.2 HIGH
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2024-33051 1 Qualcomm 578 315 5g Iot, 315 5g Iot Firmware, 9206 Lte and 575 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2025-21427 1 Qualcomm 358 205 Mobile, 205 Mobile Firmware, 215 Mobile and 355 more 2025-08-11 N/A 8.2 HIGH
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21475 1 Qualcomm 80 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 77 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
CVE-2023-33080 1 Qualcomm 732 315 5g Iot Modem, 315 5g Iot Modem Firmware, 8098 and 729 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-43536 1 Qualcomm 618 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 615 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-28563 1 Qualcomm 460 Aqt1000, Aqt1000 Firmware, Ar8031 and 457 more 2025-08-11 N/A 6.1 MEDIUM
Information disclosure in IOE Firmware while handling WMI command.
CVE-2024-9029 1 Freeimage Project 1 Freeimage 2025-08-08 N/A 7.5 HIGH
A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked to the library, resulting in a denial of service.
CVE-2023-53159 1 Sfackler 1 Openssl 2025-08-07 N/A 4.5 MEDIUM
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
CVE-2024-31081 2025-08-04 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31080 2025-08-04 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.