U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:h:qualcomm:snapdragon_x70_modem-rf_system:-:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 52 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2023-33076

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

Published: February 06, 2024; 1:16:00 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-33072

Memory corruption in Core while processing control functions.

Published: February 06, 2024; 1:16:00 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-33060

Transient DOS in Core when DDR memory check is called while DDR is not initialized.

Published: February 06, 2024; 1:15:59 AM -0500
V4.0:(not available)
V3.1: 5.5 MEDIUM
V2.0:(not available)
CVE-2023-33058

Information disclosure in Modem while processing SIB5.

Published: February 06, 2024; 1:15:59 AM -0500
V4.0:(not available)
V3.1: 9.1 CRITICAL
V2.0:(not available)
CVE-2023-33057

Transient DOS in Multi-Mode Call Processor while processing UE policy container.

Published: February 06, 2024; 1:15:59 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33049

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

Published: February 06, 2024; 1:15:59 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33046

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

Published: February 06, 2024; 1:15:58 AM -0500
V4.0:(not available)
V3.1: 7.0 HIGH
V2.0:(not available)
CVE-2023-33110

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

Published: January 02, 2024; 1:15:11 AM -0500
V4.0:(not available)
V3.1: 7.0 HIGH
V2.0:(not available)
CVE-2023-33040

Transient DOS in Data Modem during DTLS handshake.

Published: January 02, 2024; 1:15:10 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33038

Memory corruption while receiving a message in Bus Socket Transport Server.

Published: January 02, 2024; 1:15:10 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-33033

Memory corruption in Audio during playback with speaker protection.

Published: January 02, 2024; 1:15:09 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-33030

Memory corruption in HLOS while running playready use-case.

Published: January 02, 2024; 1:15:09 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-33025

Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

Published: January 02, 2024; 1:15:08 AM -0500
V4.0:(not available)
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2023-33014

Information disclosure in Core services while processing a Diag command.

Published: January 02, 2024; 1:15:08 AM -0500
V4.0:(not available)
V3.1: 6.8 MEDIUM
V2.0:(not available)
CVE-2023-33044

Transient DOS in Data modem while handling TLB control messages from the Network.

Published: December 04, 2023; 10:15:11 PM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33043

Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

Published: December 04, 2023; 10:15:11 PM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33042

Transient DOS in Modem after RRC Setup message is received.

Published: December 04, 2023; 10:15:11 PM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2023-33018

Memory corruption while using the UIM diag command to get the operators name.

Published: December 04, 2023; 10:15:10 PM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-28586

Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

Published: December 04, 2023; 10:15:09 PM -0500
V4.0:(not available)
V3.1: 6.5 MEDIUM
V2.0:(not available)
CVE-2023-28585

Memory corruption while loading an ELF segment in TEE Kernel.

Published: December 04, 2023; 10:15:09 PM -0500
V4.0:(not available)
V3.1: 8.8 HIGH
V2.0:(not available)