Home/Product/qualcomm qts110 firmware
Product

qualcomm qts110 firmware

72 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-27054
all versions
Memory corruption while processing a malformed license file during reboot.
7.8HIGH
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8HIGH
CVE-2025-21465
all versions
Information disclosure while processing the hash segment in an MBN file.
6.5MEDIUM
CVE-2025-21464
all versions
Information disclosure while reading data from an image using specified offset and size parameters.
6.5MEDIUM
CVE-2024-38426
all versions
While processing the authentication message in UE, improper authentication may lead to information disclosure.
5.4MEDIUM
CVE-2024-33056
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
8.4HIGH
CVE-2024-33016
all versions
memory corruption when an invalid firehose patch command is invoked.
6.8MEDIUM
CVE-2024-23359
all versions
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
8.2HIGH
CVE-2024-23353
all versions
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5HIGH
CVE-2024-21462
all versions
Transient DOS while loading the TA ELF file.
7.1HIGH
CVE-2024-21461
all versions
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4HIGH
CVE-2023-43551
all versions
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immedia
9.1CRITICAL
CVE-2023-28547
all versions
Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4HIGH
CVE-2023-33066
all versions
Memory corruption in Audio while processing RT proxy port register driver.
8.4HIGH
CVE-2023-33033
all versions
Memory corruption in Audio during playback with speaker protection.
8.4HIGH
CVE-2023-33032
all versions
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
9.3CRITICAL
CVE-2023-33030
all versions
Memory corruption in HLOS while running playready use-case.
9.3CRITICAL
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8HIGH
CVE-2023-33017
all versions
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
7.8HIGH
CVE-2023-28586
all versions
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
6.0MEDIUM
CVE-2023-28585
all versions
Memory corruption while loading an ELF segment in TEE Kernel.
8.2HIGH
CVE-2023-28551
all versions
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8HIGH
CVE-2023-28550
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8HIGH
CVE-2023-28546
all versions
Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8HIGH
CVE-2023-28556
all versions
Cryptographic issue in HLOS during key management.
7.1HIGH
CVE-2023-24852
all versions
Memory Corruption in Core due to secure memory access by user while loading modem image.
8.4HIGH
CVE-2023-22388
all versions
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
9.8CRITICAL
CVE-2023-22385
all versions
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
8.2HIGH
CVE-2023-28565
all versions
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
7.8HIGH
CVE-2023-21625
all versions
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
8.2HIGH
CVE-2023-21631
all versions
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from netw
7.5HIGH
CVE-2022-40521
all versions
Transient DOS due to improper authorization in Modem
7.5HIGH
CVE-2022-40507
all versions
Memory corruption due to double free in Core while mapping HLOS address to the list.
8.4HIGH
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1HIGH
CVE-2022-40505
all versions
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
8.2HIGH
CVE-2022-33304
all versions
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
7.5HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4HIGH
CVE-2022-33302
all versions
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command le
6.8MEDIUM
CVE-2022-33295
all versions
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
8.2HIGH
CVE-2022-33294
all versions
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request mes
7.5HIGH
CVE-2022-33291
all versions
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
8.2HIGH
CVE-2022-33289
all versions
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
6.8MEDIUM
CVE-2022-33287
all versions
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
8.2HIGH
CVE-2022-33259
all versions
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
9.8CRITICAL
CVE-2022-33258
all versions
Information disclosure due to buffer over-read in modem while reading configuration parameters.
8.2HIGH
CVE-2022-33231
all versions
Memory corruption due to double free in core while initializing the encryption key.
9.3CRITICAL
CVE-2022-33228
all versions
Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in head
8.2HIGH
CVE-2022-33223
all versions
Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding.
7.5HIGH
CVE-2022-33222
all versions
Information disclosure due to buffer over-read while parsing DNS response packets in Modem.
8.2HIGH
CVE-2022-33211
all versions
memory corruption in modem due to improper check while calculating size of serialized CoAP message
9.8CRITICAL
CVE-2022-25747
all versions
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message
8.2HIGH
CVE-2022-25745
all versions
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
9.8CRITICAL
CVE-2022-25740
all versions
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface
9.8CRITICAL
CVE-2022-25739
all versions
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
7.5HIGH
CVE-2022-25737
all versions
Information disclosure in modem due to missing NULL check while reading packets received from local network
7.5HIGH
CVE-2022-25731
all versions
Information disclosure in modem due to buffer over-read while processing packets from DNS server
7.5HIGH
CVE-2022-25730
all versions
Information disclosure in modem due to improper check of IP type while processing DNS server query
8.2HIGH
CVE-2022-25726
all versions
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet
8.2HIGH
CVE-2022-25678
all versions
Memory correction in modem due to buffer overwrite during coap connection
9.8CRITICAL
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4HIGH
CVE-2022-33213
all versions
Memory corruption in modem due to buffer overflow while processing a PPP packet
7.5HIGH
CVE-2022-25705
all versions
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
7.8HIGH
CVE-2022-25694
all versions
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
8.4HIGH
CVE-2022-33233
all versions
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
7.8HIGH
CVE-2022-33229
all versions
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
8.2HIGH
CVE-2022-25738
all versions
Information disclosure in modem due to buffer over-red while performing checksum of packet received
8.2HIGH
CVE-2022-25735
all versions
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
7.5HIGH
CVE-2022-25734
all versions
Denial of service in modem due to missing null check while processing IP packets with padding
7.5HIGH
CVE-2022-25733
all versions
Denial of service in modem due to null pointer dereference while processing DNS packets
7.5HIGH
CVE-2022-25732
all versions
Information disclosure in modem due to buffer over read in dns client due to missing length check
8.2HIGH
CVE-2022-25729
all versions
Memory corruption in modem due to improper length check while copying into memory
9.8CRITICAL
CVE-2022-25728
all versions
Information disclosure in modem due to buffer over-read while processing response from DNS server
8.2HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin