2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33054CRITICAL9.1Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
CVE-2023-33053HIGH7.8Memory corruption in Kernel while parsing metadata.
CVE-2023-33044HIGH7.5Transient DOS in Data modem while handling TLB control messages from the Network.
CVE-2023-33043HIGH7.5Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
CVE-2023-33042HIGH7.5Transient DOS in Modem after RRC Setup message is received.
CVE-2023-33041HIGH7.5Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
CVE-2023-33024HIGH7.8Memory corruption while sending SMS from AP firmware.
CVE-2023-33022HIGH7.8Memory corruption in HLOS while invoking IOCTL calls from user-space.
CVE-2023-33018HIGH7.8Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017HIGH7.8Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-28588HIGH7.5Transient DOS in Bluetooth Host while rfc slot allocation.
CVE-2023-28587HIGH7.8Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
CVE-2023-28586MEDIUM6.5Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28585HIGH8.8Memory corruption while loading an ELF segment in TEE Kernel.
CVE-2023-28580HIGH7.8Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
CVE-2023-28579HIGH7.8Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length.
CVE-2023-28551HIGH7.8Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input a...
CVE-2023-28550HIGH7.8Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-28546HIGH7.8Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-22668HIGH7.8Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
CVE-2023-22383HIGH7.8Memory Corruption in camera while installing a fd for a particular DMA buffer.
CVE-2023-21634HIGH7.8Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
CVE-2023-48698CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre...
CVE-2023-48697CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre...
CVE-2023-48696CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now