CVEs (257)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 43Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+40 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |
1Qualcomm 331315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+328 moreOct 3, 2025 Sep 2, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 memory corruption when an invalid firehose patch command is invoked. |
1Qualcomm 177Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+174 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). |
1Qualcomm 2309205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+227 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Cryptographic issue while parsing RSA keys in COBR format. |
1Qualcomm 159205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+156 moreOct 3, 2025 Sep 2, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
1Qualcomm 102Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+99 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. |
1Qualcomm 164Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+161 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. |
1Qualcomm 179Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+176 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. |
1Qualcomm 151Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+148 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call to set metainfo. |
1Qualcomm 96Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6800 Firmware+93 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TID-to-link mapping IE elements. |
1Qualcomm 148Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+145 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping action frame. |
1Qualcomm 150Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+147 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. |
1Qualcomm 192Ar8035 Firmware Csr8811 FirmwareFastconnect 6200 Firmware+189 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 169Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+166 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 246Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+243 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing fragments of MBSSID IE from beacon frame. |