Peterpark

#2546of 53,624
97.1Total CVSS
Vulnerabilities · 13
Medium
2
High
10
Critical
1
PT-2022-9953
7.8
2022-01-03
Qualcomm · Snapdragon Mobile · CVE-2021-30267
**Name of the Vulnerable Software and Affected Versions** Snapdragon Auto (affected versions not specified) Snapdragon Compute (affected versions not specified) Snapdragon Connectivity (affected versions not specified) Snapdragon Consumer IOT (affected versions not specified) Snapdragon Industrial IOT (affected versions not specified) Snapdragon Mobile (affected versions not specified) **Description** The issue is related to possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands. This affects various Snapdragon products, including Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, and Mobile. **Recommendations** For Snapdragon Auto, update to a version that includes proper input validation for FTM ARA commands. For Snapdragon Compute, update to a version that includes proper input validation for FTM ARA commands. For Snapdragon Connectivity, update to a version that includes proper input validation for FTM ARA commands. For Snapdragon Consumer IOT, update to a version that includes proper input validation for FTM ARA commands. For Snapdragon Industrial IOT, update to a version that includes proper input validation for FTM ARA commands. For Snapdragon Mobile, update to a version that includes proper input validation for FTM ARA commands. As a temporary workaround, consider disabling the use of FTM ARA commands until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the vulnerable `FTM ARA` commands in the affected products until the issue is resolved.
PT-2019-11921
7.2
2019-12-18
Qualcomm · Snapdragon Wired Infrastructure/Networking · CVE-2019-10536
**Name of the Vulnerable Software and Affected Versions** Qualcomm Snapdragon Auto versions prior to the fixed version Qualcomm Snapdragon Compute versions prior to the fixed version Qualcomm Snapdragon Consumer Electronics Connectivity versions prior to the fixed version Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Industrial IOT versions prior to the fixed version Qualcomm Snapdragon Mobile versions prior to the fixed version Qualcomm Snapdragon Voice & Music versions prior to the fixed version Qualcomm Snapdragon Wired Infrastructure and Networking versions prior to the fixed version **Description** A potential double free scenario exists if the driver receives another DIAG EVENT LOG SUPPORTED event from firmware as the pointer is not set to NULL on the first call. This issue affects various Qualcomm Snapdragon products, including Auto, Compute, Consumer Electronics Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wired Infrastructure and Networking. **Recommendations** For Qualcomm Snapdragon Auto, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Compute, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Consumer Electronics Connectivity, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Consumer IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Industrial IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Mobile, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Voice & Music, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Wired Infrastructure and Networking, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.