CVEs (201)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 150Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+147 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. |
1Qualcomm 192Ar8035 Firmware Csr8811 FirmwareFastconnect 6200 Firmware+189 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 169Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+166 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 246Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+243 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
1Qualcomm 236215 Mobile Platform Firmware Apq8017 FirmwareApq8037 Firmware+233 moreNov 25, 2024 Aug 5, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
1Qualcomm 208Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+205 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during session sign renewal request calls in HLOS. |
1Qualcomm 141Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+138 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when keymaster operation imports a shared key. |
1Qualcomm 220205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+217 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
1Qualcomm 2229205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+219 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
1Qualcomm 2579205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+254 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing key blob passed by the user. |
1Qualcomm 309315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+306 moreNov 21, 2024 Jul 1, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while loading the TA ELF file. |
1Qualcomm 311215 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+308 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
1Qualcomm 303315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+300 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parse fils IE with length equal to 1. |
1Qualcomm 65Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+62 moreAug 11, 2025 Feb 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
1Qualcomm 232315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+229 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
1Qualcomm 280Aqt1000 Firmware Ar8035 FirmwareAr9380 Firmware+277 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. |
1Qualcomm 69Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+66 moreAug 11, 2025 Feb 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. |