Vulnerabilities (CVE)

Filtered by CWE-126
Total 521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33047 1 Qualcomm 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more 2026-06-17 N/A 8.4 HIGH
Memory corruption when the captureRead QDCM command is invoked from user-space.
CVE-2024-33043 1 Qualcomm 406 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 403 more 2026-06-17 N/A 5.5 MEDIUM
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33037 1 Qualcomm 102 C-v2x 9150, C-v2x 9150 Firmware, Fastconnect 6800 and 99 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
CVE-2024-33026 1 Qualcomm 330 Ar8035, Ar8035 Firmware, Csr8811 and 327 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-33025 1 Qualcomm 338 Csr8811, Csr8811 Firmware, Fastconnect 6800 and 335 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33020 1 Qualcomm 196 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 193 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33019 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Csr8811 and 295 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-33018 1 Qualcomm 302 Ar8035, Ar8035 Firmware, Csr8811 and 299 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.
CVE-2024-33015 1 Qualcomm 390 Ar8035, Ar8035 Firmware, Csr8811 and 387 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVE-2024-33014 1 Qualcomm 650 315 5g Iot Modem, 315 5g Iot Modem Firmware, 860 Mobile Platform and 647 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33013 1 Qualcomm 340 Ar8035, Ar8035 Firmware, Csr8811 and 337 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
CVE-2024-33012 1 Qualcomm 498 Ar8035, Ar8035 Firmware, Ar9380 and 495 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2024-33011 1 Qualcomm 498 Ar8035, Ar8035 Firmware, Ar9380 and 495 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
CVE-2024-31082 2026-06-17 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31081 2026-06-17 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-31080 2026-06-17 N/A 7.3 HIGH
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.
CVE-2024-30079 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2026-06-17 N/A 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2024-30071 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2026-06-17 N/A 4.7 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-30039 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2026-06-17 N/A 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-28902 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2026-06-17 N/A 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability