CVEs (586)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 81Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+78 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. |
1Qualcomm 350315 5g Iot Modem Firmware 9206 Lte Modem FirmwareApq8017 Firmware+347 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
1Qualcomm 227315 5g Iot Modem Firmware 9206 Lte Modem FirmwareApq8017 Firmware+224 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
1Qualcomm 130Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+127 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
1Qualcomm 122Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+119 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. |
1Qualcomm 122Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+119 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
1Qualcomm 304315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+301 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
1Qualcomm 120Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+117 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while running VK synchronization with KASAN enabled. |
1Qualcomm 102Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+99 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in wearables while processing data from AON. |
1Qualcomm 284315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+281 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware while parsing a BTM request. |
1Qualcomm 139315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+136 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in Data Modem during DTLS handshake. |
1Qualcomm 139315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+136 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while receiving a message in Bus Socket Transport Server. |
1Qualcomm 259315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+256 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio during playback with speaker protection. |
1Qualcomm 293315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+290 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in HLOS while running playready use-case. |
1Qualcomm 236315 5g Iot Modem Firmware Apq8017 FirmwareApq8064au Firmware+233 moreOct 28, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
1Qualcomm 147Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+144 moreOct 28, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. |
1Qualcomm 257315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+254 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
1Qualcomm 90Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+87 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. |
1Qualcomm 223315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+220 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing a NULL buffer while parsing WLAN vdev. |