CVE-2024-33038
HIGHDescription
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
Is your site exposed to CVE-2024-33038?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| qualcomm | fastconnect_6700_firmware |
| qualcomm | fastconnect_6700 |
| qualcomm | fastconnect_6900_firmware |
| qualcomm | fastconnect_6900 |
| qualcomm | fastconnect_7800_firmware |
| qualcomm | fastconnect_7800 |
| qualcomm | qcm4490_firmware |
| qualcomm | qcm4490 |
| qualcomm | qcm5430_firmware |
| qualcomm | qcm5430 |
| qualcomm | qcm6490_firmware |
| qualcomm | qcm6490 |
| qualcomm | qcm8550_firmware |
| qualcomm | qcm8550 |
| qualcomm | qcs4490_firmware |
| qualcomm | qcs4490 |
| qualcomm | qcs5430_firmware |
| qualcomm | qcs5430 |
| qualcomm | qcs6490_firmware |
| qualcomm | qcs6490 |
| qualcomm | qcs8550_firmware |
| qualcomm | qcs8550 |
| qualcomm | video_collaboration_vc3_platform_firmware |
| qualcomm | video_collaboration_vc3_platform |
| qualcomm | sd_8_gen1_5g_firmware |
| qualcomm | sd_8_gen1_5g |
| qualcomm | sg8275p_firmware |
| qualcomm | sg8275p |
| qualcomm | sm8550p_firmware |
| qualcomm | sm8550p |
| qualcomm | sm8635_firmware |
| qualcomm | sm8635 |
| qualcomm | snapdragon_4_gen_2_firmware |
| qualcomm | snapdragon_4_gen_2 |
| qualcomm | snapdragon_8_gen_1_firmware |
| qualcomm | snapdragon_8_gen_1 |
| qualcomm | snapdragon_8_gen_2_firmware |
| qualcomm | snapdragon_8_gen_2 |
| qualcomm | snapdragon_8_gen_3_firmware |
| qualcomm | snapdragon_8_gen_3 |
| qualcomm | snapdragon_8\+_gen_1_firmware |
| qualcomm | snapdragon_8\+_gen_1 |
| qualcomm | snapdragon_8\+_gen_2_firmware |
| qualcomm | snapdragon_8\+_gen_2 |
| qualcomm | snapdragon_ar2_gen_1_firmware |
| qualcomm | snapdragon_ar2_gen_1 |
| qualcomm | ssg2115p_firmware |
| qualcomm | ssg2115p |
| qualcomm | ssg2125p_firmware |
| qualcomm | ssg2125p |
| qualcomm | sxr1230p_firmware |
| qualcomm | sxr1230p |
| qualcomm | talynplus_firmware |
| qualcomm | talynplus |
| qualcomm | wcd9370_firmware |
| qualcomm | wcd9370 |
| qualcomm | wcd9375_firmware |
| qualcomm | wcd9375 |
| qualcomm | wcd9380_firmware |
| qualcomm | wcd9380 |
| qualcomm | wcd9385_firmware |
| qualcomm | wcd9385 |
| qualcomm | wcd9390_firmware |
| qualcomm | wcd9390 |
| qualcomm | wcd9395_firmware |
| qualcomm | wcd9395 |
| qualcomm | wcn3950_firmware |
| qualcomm | wcn3950 |
| qualcomm | wcn3988_firmware |
| qualcomm | wcn3988 |
| qualcomm | wcn6740_firmware |
| qualcomm | wcn6740 |
| qualcomm | wcn6755_firmware |
| qualcomm | wcn6755 |
| qualcomm | wsa8810_firmware |
| qualcomm | wsa8810 |
| qualcomm | wsa8815_firmware |
| qualcomm | wsa8815 |
| qualcomm | wsa8830_firmware |
| qualcomm | wsa8830 |
| qualcomm | wsa8832_firmware |
| qualcomm | wsa8832 |
| qualcomm | wsa8835_firmware |
| qualcomm | wsa8835 |
| qualcomm | wsa8840_firmware |
| qualcomm | wsa8840 |
| qualcomm | wsa8845_firmware |
| qualcomm | wsa8845 |
| qualcomm | wsa8845h_firmware |
| qualcomm | wsa8845h |
References
Frequently Asked Questions
What is CVE-2024-33038? +
How severe is CVE-2024-33038? +
What products are affected by CVE-2024-33038? +
How do I check if I'm vulnerable to CVE-2024-33038? +
Related Vulnerabilities
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM …
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow …
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local …
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before …
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before …