U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:qualcomm:mdm9205_firmware:-:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 197 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2023-21651

Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.

Published: August 08, 2023; 6:15:13 AM -0400
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-21626

Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

Published: August 08, 2023; 6:15:13 AM -0400
V3.1: 7.1 HIGH
V2.0:(not available)
CVE-2023-21625

Information disclosure in Network Services due to buffer over-read while the device receives DNS response.

Published: August 08, 2023; 6:15:13 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33295

Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.

Published: April 13, 2023; 3:15:18 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33294

Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message.

Published: April 13, 2023; 3:15:18 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33259

Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.

Published: April 13, 2023; 3:15:15 AM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2022-33258

Information disclosure due to buffer over-read in modem while reading configuration parameters.

Published: April 13, 2023; 3:15:15 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33231

Memory corruption due to double free in core while initializing the encryption key.

Published: April 13, 2023; 3:15:15 AM -0400
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2022-33228

Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header.

Published: April 13, 2023; 3:15:14 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33223

Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding.

Published: April 13, 2023; 3:15:14 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33222

Information disclosure due to buffer over-read while parsing DNS response packets in Modem.

Published: April 13, 2023; 3:15:14 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-33211

memory corruption in modem due to improper check while calculating size of serialized CoAP message

Published: April 13, 2023; 3:15:13 AM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2022-25747

Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message

Published: April 13, 2023; 3:15:13 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-25745

Memory corruption in modem due to improper input validation while handling the incoming CoAP message

Published: April 13, 2023; 3:15:13 AM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2022-25740

Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface

Published: April 13, 2023; 3:15:12 AM -0400
V3.1: 9.8 CRITICAL
V2.0:(not available)
CVE-2022-25739

Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call

Published: April 13, 2023; 3:15:12 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-25737

Information disclosure in modem due to missing NULL check while reading packets received from local network

Published: April 13, 2023; 3:15:12 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-25731

Information disclosure in modem due to buffer over-read while processing packets from DNS server

Published: April 13, 2023; 3:15:11 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-25730

Information disclosure in modem due to improper check of IP type while processing DNS server query

Published: April 13, 2023; 3:15:11 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2022-25726

Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet

Published: April 13, 2023; 3:15:10 AM -0400
V3.1: 7.5 HIGH
V2.0:(not available)