threat
engine
.sh
Back
·
··:··
Home
/
Product
/
qualcomm ipq5018 firmware
Product
qualcomm ipq5018 firmware
107 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-21664
all versions
Memory Corruption in Core Platform while printing the response buffer in log.
7.8
HIGH
CVE-2023-21662
all versions
Memory corruption in Core Platform while printing the response buffer in log.
7.8
HIGH
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4
HIGH
CVE-2022-40530
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
8.4
HIGH
CVE-2022-40527
all versions
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
7.5
HIGH
CVE-2022-33309
all versions
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
7.5
HIGH
CVE-2022-25655
all versions
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
8.4
HIGH
CVE-2022-40514
all versions
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc respo
9.8
CRITICAL
CVE-2022-40513
all versions
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
7.5
HIGH
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5
HIGH
CVE-2022-40502
all versions
Transient DOS due to improper input validation in WLAN Host.
7.5
HIGH
CVE-2022-34146
all versions
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
7.5
HIGH
CVE-2022-34145
all versions
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
7.5
HIGH
CVE-2022-33306
all versions
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
7.5
HIGH
CVE-2022-33279
all versions
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
9.8
CRITICAL
CVE-2022-33277
all versions
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
8.4
HIGH
CVE-2022-33271
all versions
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
8.2
HIGH
CVE-2022-33243
all versions
Memory corruption due to improper access control in Qualcomm IPC.
8.4
HIGH
CVE-2022-33286
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
7.5
HIGH
CVE-2022-33285
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
7.5
HIGH
CVE-2022-33284
all versions
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
8.2
HIGH
CVE-2022-33283
all versions
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
8.2
HIGH
CVE-2022-33276
all versions
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
8.4
HIGH
CVE-2022-33253
all versions
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
7.5
HIGH
CVE-2022-33252
all versions
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
8.2
HIGH
CVE-2022-25722
all versions
Information exposure in DSP services due to improper handling of freeing memory
6.0
MEDIUM
CVE-2022-33238
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
7.5
HIGH
CVE-2022-33235
all versions
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto
8.2
HIGH
CVE-2022-25677
all versions
Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
6.7
MEDIUM
CVE-2022-33239
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
7.5
HIGH
CVE-2022-33237
all versions
Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2022-33236
all versions
Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdrag
7.5
HIGH
CVE-2022-25667
all versions
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking
7.5
HIGH
CVE-2022-25749
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2022-25748
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
9.8
CRITICAL
CVE-2022-25736
all versions
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Comput
7.5
HIGH
CVE-2022-25719
all versions
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdrag
8.2
HIGH
CVE-2022-25666
all versions
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon
6.7
MEDIUM
CVE-2022-25652
all versions
Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking
9.0
CRITICAL
CVE-2021-35129
all versions
Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, S
7.8
HIGH
CVE-2021-35071
all versions
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of
5.5
MEDIUM
CVE-2021-35103
all versions
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Sn
7.8
HIGH
CVE-2021-35088
all versions
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Sn
8.2
HIGH
CVE-2021-35069
all versions
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2021-30325
all versions
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdr
6.7
MEDIUM
CVE-2021-30324
all versions
Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote proce
6.7
MEDIUM
CVE-2021-30313
all versions
Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon
6.7
MEDIUM
CVE-2021-30337
all versions
Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdrago
8.4
HIGH
CVE-2021-30335
all versions
Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Sn
8.4
HIGH
CVE-2021-30303
all versions
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon
7.8
HIGH
CVE-2021-30272
all versions
Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon
7.3
HIGH
CVE-2021-30271
all versions
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto,
7.3
HIGH
CVE-2021-30266
all versions
Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon
6.7
MEDIUM
CVE-2021-30264
all versions
Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon
6.7
MEDIUM
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0
CRITICAL
CVE-2021-1903
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
5.3
MEDIUM
CVE-2021-30312
all versions
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon
7.5
HIGH
CVE-2021-30302
all versions
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Comput
7.5
HIGH
CVE-2021-30288
all versions
Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Sn
8.4
HIGH
CVE-2021-1980
all versions
Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2021-30260
all versions
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist
8.4
HIGH
CVE-2021-1976
all versions
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Com
9.8
CRITICAL
CVE-2021-1974
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
7.5
HIGH
CVE-2021-1971
all versions
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
7.5
HIGH
CVE-2021-1960
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
6.5
MEDIUM
CVE-2021-1948
all versions
Possible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snap
7.5
HIGH
CVE-2021-1941
all versions
Possible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute,
7.5
HIGH
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3
HIGH
CVE-2021-1972
all versions
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snap
9.8
CRITICAL
CVE-2021-1928
all versions
Buffer over read could occur due to incorrect check of buffer size while flashing emmc devices in Snapdragon Connectivity, Snapdra
4.6
MEDIUM
CVE-2020-11301
all versions
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapd
9.1
CRITICAL
CVE-2021-1965
all versions
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute,
9.8
CRITICAL
CVE-2021-1964
all versions
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdrag
7.5
HIGH
CVE-2021-1954
all versions
Possible buffer over read due to improper validation of data pointer while parsing FILS indication IE in Snapdragon Auto, Snapdrag
7.5
HIGH
CVE-2021-1953
all versions
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Sna
7.5
HIGH
CVE-2021-1945
all versions
Possible out of bound read due to lack of length check of Bandwidth-NSS IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
7.5
HIGH
CVE-2021-1943
all versions
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response
7.5
HIGH
CVE-2021-1938
all versions
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapd
7.5
HIGH
CVE-2021-1937
all versions
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdr
7.5
HIGH
CVE-2020-11267
all versions
Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdra
8.4
HIGH
CVE-2020-11241
all versions
Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attribute in Sn
7.5
HIGH
CVE-2020-11238
all versions
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdragon Compute,
7.5
HIGH
CVE-2020-11235
all versions
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdrag
7.8
HIGH
CVE-2020-11159
all versions
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame po
9.1
CRITICAL
CVE-2020-11134
all versions
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN rangin
9.8
CRITICAL
CVE-2020-11126
all versions
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon
9.1
CRITICAL
CVE-2021-1927
all versions
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Com
8.4
HIGH
CVE-2021-1925
all versions
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compu
7.5
HIGH
CVE-2021-1915
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2020-11289
all versions
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2020-11296
all versions
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snap
7.5
HIGH
CVE-2020-11281
all versions
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclos
7.5
HIGH
CVE-2020-11280
all versions
Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due
7.5
HIGH
CVE-2020-11278
all versions
Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snap
7.5
HIGH
CVE-2020-11276
all versions
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation
9.1
CRITICAL
CVE-2020-11275
all versions
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapd
9.1
CRITICAL
CVE-2020-11270
all versions
Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM
7.5
HIGH
CVE-2020-11204
all versions
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for par
7.8
HIGH
CVE-2020-11119
all versions
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdra
7.5
HIGH
CVE-2020-3704
all versions
u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device may lead per
7.5
HIGH
CVE-2020-11174
all versions
u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdragon Auto,
7.8
HIGH
CVE-2020-11173
all versions
u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon
7.0
HIGH
CVE-2020-11162
all versions
u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI device side' in
7.8
HIGH
CVE-2020-11125
all versions
u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devices' in Sna
7.8
HIGH
CVE-2020-3675
all versions
u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdra
9.8
CRITICAL
CVE-2020-3669
all versions
u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Snapdragon Co
9.8
CRITICAL
CVE-2020-3667
all versions
u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdrago
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin