Vulnerabilities (CVE)

Filtered by CWE-120
Total 3793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43519 1 Qualcomm 268 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 265 more 2025-08-11 N/A 7.3 HIGH
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
CVE-2023-43556 1 Qualcomm 136 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 133 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Hypervisor when platform information mentioned is not aligned.
CVE-2024-33042 1 Qualcomm 406 205, 205 Firmware, 215 and 403 more 2025-08-11 N/A 7.8 HIGH
Memory corruption when Alternative Frequency offset value is set to 255.
CVE-2023-28547 1 Qualcomm 604 215 Mobile, 215 Mobile Firmware, 315 5g Iot and 601 more 2025-08-11 N/A 8.4 HIGH
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2025-27043 1 Qualcomm 412 Ar8035, Ar8035 Firmware, Csr8811 and 409 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing manipulated payload in video firmware.
CVE-2023-43542 1 Qualcomm 418 9205 Lte Modem, 9205 Lte Modem Firmware, Aqt1000 and 415 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2023-33035 1 Qualcomm 288 Apq5053-aa, Apq5053-aa Firmware, Ar8035 and 285 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while invoking callback function of AFE from ADSP.
CVE-2024-33054 1 Qualcomm 66 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 63 more 2025-08-11 N/A 7.8 HIGH
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
CVE-2023-33068 1 Qualcomm 226 9206 Lte Modem, 9206 Lte Modem Firmware, Aqt1000 and 223 more 2025-08-11 N/A 6.7 MEDIUM
Memory corruption in Audio while processing IIR config data from AFE calibration block.
CVE-2023-28546 1 Qualcomm 560 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 557 more 2025-08-11 N/A 7.8 HIGH
Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-33069 1 Qualcomm 226 9206 Lte Modem, 9206 Lte Modem Firmware, Aqt1000 and 223 more 2025-08-11 N/A 6.7 MEDIUM
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
CVE-2023-28579 1 Qualcomm 68 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 65 more 2025-08-11 N/A 6.7 MEDIUM
Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
CVE-2023-28539 1 Qualcomm 314 Ar8035, Ar8035 Firmware, Ar9380 and 311 more 2025-08-11 N/A 6.6 MEDIUM
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
CVE-2023-43548 1 Qualcomm 284 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 281 more 2025-08-11 N/A 7.3 HIGH
Memory corruption while parsing qcp clip with invalid chunk data size.
CVE-2023-33077 1 Qualcomm 192 Aqt1000, Aqt1000 Firmware, Ar8035 and 189 more 2025-08-11 N/A 6.7 MEDIUM
Memory corruption in HLOS while converting from authorization token to HIDL vector.
CVE-2024-45541 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 99 more 2025-08-11 N/A 7.8 HIGH
Memory corruption when IOCTL call is invoked from user-space to read board data.
CVE-2024-21480 1 Qualcomm 230 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 227 more 2025-08-11 N/A 7.3 HIGH
Memory corruption while playing audio file having large-sized input buffer.
CVE-2023-33072 1 Qualcomm 490 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 487 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Core while processing control functions.
CVE-2025-2017 1 Ashlar 1 Cobalt 2025-08-08 N/A 7.8 HIGH
Ashlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25240.
CVE-2025-8170 1 Totolink 2 T6, T6 Firmware 2025-08-07 9.0 HIGH 8.8 HIGH
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the function tcpcheck_net of the file /router/meshSlaveDlfw of the component MQTT Packet Handler. The manipulation of the argument serverIp leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.