Vulnerabilities (CVE)

Filtered by CWE-126
Total 275 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-27029 1 Qualcomm 134 Fastconnect 7800, Fastconnect 7800 Firmware, Immersive Home 3210 Platform and 131 more 2025-08-20 N/A 7.5 HIGH
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
CVE-2024-53019 1 Qualcomm 162 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 159 more 2025-08-20 N/A 8.2 HIGH
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
CVE-2025-27065 1 Qualcomm 300 Ar8035, Ar8035 Firmware, Fastconnect 6800 and 297 more 2025-08-20 N/A 7.5 HIGH
Transient DOS while processing a frame with malformed shared-key descriptor.
CVE-2025-21421 1 Qualcomm 90 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 87 more 2025-08-19 N/A 7.8 HIGH
Memory corruption while processing escape code in API.
CVE-2025-21457 1 Qualcomm 30 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 27 more 2025-08-19 N/A 6.1 MEDIUM
Information disclosure while opening a fastrpc session when domain is not sanitized.
CVE-2025-27068 1 Qualcomm 32 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6900 and 29 more 2025-08-18 N/A 7.8 HIGH
Memory corruption while processing an IOCTL command with an arbitrary address.
CVE-2025-53736 1 Microsoft 6 365 Apps, Office, Office Long Term Servicing Channel and 3 more 2025-08-18 N/A 6.8 MEDIUM
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2024-21459 1 Qualcomm 350 Ar8035, Ar8035 Firmware, Ar9380 and 347 more 2025-08-15 N/A 6.5 MEDIUM
Information disclosure while handling beacon or probe response frame in STA.
CVE-2021-34584 2 Codesys, Wago 55 Codesys, 750-8202, 750-8202 Firmware and 52 more 2025-08-15 6.4 MEDIUM 9.1 CRITICAL
Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
CVE-2024-52877 1 Insyde 1 Insydeh2o 2025-08-15 N/A 7.5 HIGH
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read.
CVE-2024-52878 1 Insyde 1 Insydeh2o 2025-08-15 N/A 7.5 HIGH
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.
CVE-2024-52879 1 Insyde 1 Insydeh2o 2025-08-15 N/A 7.5 HIGH
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.
CVE-2023-33047 1 Qualcomm 356 Ar8035, Ar8035 Firmware, Ar9380 and 353 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing no-inherit IES.
CVE-2023-33065 1 Qualcomm 208 Aqt1000, Aqt1000 Firmware, Ar8035 and 205 more 2025-08-11 N/A 6.1 MEDIUM
Information disclosure in Audio while accessing AVCS services from ADSP payload.
CVE-2025-27057 1 Qualcomm 424 Ar8035, Ar8035 Firmware, Csr8811 and 421 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2023-33098 1 Qualcomm 526 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 523 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
CVE-2024-33048 1 Qualcomm 378 Ar8035, Ar8035 Firmware, Csr8811 and 375 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2023-43533 1 Qualcomm 476 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 473 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2024-45558 1 Qualcomm 366 Ar8035, Ar8035 Firmware, Csr8811 and 363 more 2025-08-11 N/A 7.5 HIGH
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
CVE-2023-33062 1 Qualcomm 580 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 577 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing a BTM request.