📦 Apq5053 Aa Firmware

by Qualcomm

🔍 What is Apq5053 Aa Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33054

CRITICAL CVSS 9.1 Dec 5, 2023

CVE-2023-33054 is a cryptographic vulnerability in Qualcomm's GPS HLOS driver that allows improper authentication when downloading GNSS assistance data. This affects Android devices with Qualcomm chip...

CVE-2023-28540

CRITICAL CVSS 9.1 Oct 3, 2023

This vulnerability in Qualcomm Data Modem chips allows attackers to bypass TLS authentication during handshake, potentially enabling man-in-the-middle attacks. It affects devices using vulnerable Qual...

CVE-2023-33087

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability involves memory corruption in Qualcomm's Core component while processing RX intent requests, potentially allowing attackers to execute arbitrary code or cause denial of service. It ...

CVE-2023-33070

HIGH CVSS 7.1 Dec 5, 2023

CVE-2023-33070 is a vulnerability in Qualcomm Automotive OS where improper authentication to secure IO calls allows attackers to cause a transient denial-of-service condition. This affects automotive ...

CVE-2023-33079

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability allows memory corruption in the Audio subsystem when processing invalid audio recording data from the ADSP (Audio Digital Signal Processor). It affects Qualcomm devices with vulnera...

CVE-2023-33017

HIGH CVSS 7.8 Dec 5, 2023

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices with vulnerable firmware, potentially allowing attac...

CVE-2023-33022

HIGH CVSS 8.4 Dec 5, 2023

This vulnerability allows memory corruption in the High-Level Operating System (HLOS) when user-space applications make specific IOCTL calls to Qualcomm hardware components. Attackers could exploit th...

CVE-2023-33034

HIGH CVSS 7.8 Oct 3, 2023

This vulnerability allows memory corruption while parsing ADSP response commands in Qualcomm chipsets, potentially enabling remote code execution. It affects devices using vulnerable Qualcomm componen...

CVE-2023-24850

HIGH CVSS 7.8 Oct 3, 2023

This vulnerability allows memory corruption in the High-Level Operating System (HLOS) when importing cryptographic keys into the KeyMaster Trusted Application on Qualcomm chipsets. Attackers could pot...

CVE-2023-24848

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows information disclosure in Qualcomm data modems during VoLTE calls when an undefined RTCP FB line value is processed. Attackers could potentially access sensitive information ...

CVE-2023-22385

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows memory corruption in Qualcomm data modem chipsets during mobile-originated or mobile-terminated VoLTE calls. Attackers could potentially execute arbitrary code or cause denia...

CVE-2023-28560

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in the WLAN Hardware Abstraction Layer (HAL) when processing devIndex values from untrusted WMI payloads. Attackers could potentially execute arbitrary code...

CVE-2022-33275

HIGH CVSS 8.4 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm WLAN hardware abstraction layer due to improper array index validation. Attackers could potentially execute arbitrary code or cause denial of se...

CVE-2023-28537

HIGH CVSS 8.4 Aug 8, 2023

This vulnerability allows memory corruption in Qualcomm's audio processing module (COmxApeDec) due to integer overflow during memory allocation. Attackers could potentially execute arbitrary code or c...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2022-40504

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows a denial-of-service (DoS) attack on mobile devices by sending a specially crafted Downlink Data Indication message to the modem. When exploited, it triggers a reachable asser...

CVE-2023-21666

HIGH CVSS 8.4 May 2, 2023

CVE-2023-21666 is a memory corruption vulnerability in Qualcomm's Adreno GPU driver (KGSL) that allows attackers to access sensitive data from graphics memory pools. This affects Android devices with ...

CVE-2022-40503

HIGH CVSS 8.2 Apr 13, 2023

This vulnerability allows attackers to read sensitive information from Bluetooth-enabled devices during A2DP audio streaming. It affects devices with Qualcomm Bluetooth chipsets that have not been pat...