CVEs (361)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 261315 5g Iot Modem Firmware Apq8017 FirmwareAqt1000 Firmware+258 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
1Qualcomm 95Aqt1000 Firmware Ar8035 FirmwareC V2x 9150 Firmware+92 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in HLOS while converting from authorization token to HIDL vector. |
1Qualcomm 239315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+236 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Core while processing control functions. |
1Qualcomm 1109206 Lte Modem Firmware Aqt1000 FirmwareAr8035 Firmware+107 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while processing the calibration data returned from ACDB loader. |
1Qualcomm 1109206 Lte Modem Firmware Aqt1000 FirmwareAr8035 Firmware+107 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while processing IIR config data from AFE calibration block. |
1Qualcomm 1109206 Lte Modem Firmware Aqt1000 FirmwareAr8035 Firmware+107 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
1Qualcomm 101Aqt1000 Firmware Ar8035 FirmwareC V2x 9150 Firmware+98 moreAug 11, 2025 Feb 6, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Information disclosure in Audio while accessing AVCS services from ADSP payload. |
1Qualcomm 88Aqt1000 Firmware Ar8035 FirmwareC V2x 9150 Firmware+85 moreAug 11, 2025 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS in Audio when invoking callback function of ASM driver. |
1Qualcomm 350315 5g Iot Modem Firmware 9206 Lte Modem FirmwareApq8017 Firmware+347 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
1Qualcomm 227315 5g Iot Modem Firmware 9206 Lte Modem FirmwareApq8017 Firmware+224 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
1Qualcomm 102Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+99 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. |
1Qualcomm 304315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+301 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
1Qualcomm 284315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+281 moreAug 11, 2025 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware while parsing a BTM request. |
1Qualcomm 259315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+256 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Audio during playback with speaker protection. |
1Qualcomm 1179205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+114 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. |
1Qualcomm 293315 5g Iot Modem Firmware 9205 Lte Modem Firmware9206 Lte Modem Firmware+290 moreNov 21, 2024 Jan 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in HLOS while running playready use-case. |
1Qualcomm 236315 5g Iot Modem Firmware Apq8017 FirmwareApq8064au Firmware+233 moreOct 28, 2025 Dec 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
1Qualcomm 257315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+254 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
1Qualcomm 121Ar8035 Firmware Csr8811 FirmwareFastconnect 6900 Firmware+118 moreNov 21, 2024 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware while processing a FTMR frame. |
1Qualcomm 223315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+220 moreAug 11, 2025 Dec 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing a NULL buffer while parsing WLAN vdev. |