CVEs (270)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 11Qca6584au Firmware Qca6698aq FirmwareQca9367 Firmware+8 moreOct 16, 2024 Oct 7, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. |
1Qualcomm 282315 5g Iot Firmware 9206 Lte FirmwareApq8017 Firmware+279 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
1Qualcomm 252Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+249 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
1Qualcomm 175Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+172 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
1Qualcomm 159205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+156 moreOct 3, 2025 Sep 2, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. |
1Qualcomm 123Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+120 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while allocating memory in HGSL driver. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call to set metainfo. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 169Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+166 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 246Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+243 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
1Qualcomm 247205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
1Qualcomm 94Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6800 Firmware+91 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS during music playback of ALAC content. |
1Qualcomm 341Apq8064au Firmware Aqt1000 FirmwareAr8035 Firmware+338 moreNov 21, 2024 Jul 1, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when allocating and accessing an entry in an SMEM partition. |
1Qualcomm 234205 Mobile Firmware 215 Mobile Firmware315 5g Iot Modem Firmware+231 moreAug 11, 2025 Jun 3, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
1Qualcomm 229215 Mobile Firmware 315 5g Iot Modem FirmwareAqt1000 Firmware+226 moreAug 11, 2025 May 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when the payload received from firmware is not as per the expected protocol size. |
1Qualcomm 90Ar8035 Firmware C V2x 9150 FirmwareCsrb31024 Firmware+87 moreAug 11, 2025 May 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
1Qualcomm 56Ar8035 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+53 moreJan 15, 2025 May 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when the bandpass filter order received from AHAL is not within the expected range. |