CVEs (449)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 90205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+87 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table. |
1Qualcomm 151Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+148 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. |
1Qualcomm 123Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+120 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while allocating memory in HGSL driver. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call to set metainfo. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 246Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+243 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
1Qualcomm 236215 Mobile Platform Firmware Apq8017 FirmwareApq8037 Firmware+233 moreNov 25, 2024 Aug 5, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
1Qualcomm 208Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+205 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during session sign renewal request calls in HLOS. |
1Qualcomm 247205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
1Qualcomm 220205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+217 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
1Qualcomm 341Apq8064au Firmware Aqt1000 FirmwareAr8035 Firmware+338 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when allocating and accessing an entry in an SMEM partition. |
1Qualcomm 2229205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+219 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
1Qualcomm 2579205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+254 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing key blob passed by the user. |
1Qualcomm 309315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+306 moreNov 21, 2024 Jul 1, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while loading the TA ELF file. |
1Qualcomm 311215 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+308 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
1Qualcomm 234205 Mobile Firmware 215 Mobile Firmware315 5g Iot Modem Firmware+231 moreAug 11, 2025 Jun 3, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
1Qualcomm 2029205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+199 moreAug 11, 2025 Jun 3, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. |
1Qualcomm 229215 Mobile Firmware 315 5g Iot Modem FirmwareAqt1000 Firmware+226 moreAug 11, 2025 May 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when the payload received from firmware is not as per the expected protocol size. |