CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 61C V2x 9150 Firmware Csrb31024 FirmwareFastconnect 6800 Firmware+58 moreFeb 5, 2025 Feb 3, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Memory corruption while parsing the memory map info in IOCTL calls. |
1Qualcomm 56Ar8035 Firmware C V2x 9150 FirmwareFastconnect 6900 Firmware+53 moreFeb 5, 2025 Feb 3, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure while processing IO control commands. |
1Qualcomm 71Ar8035 Firmware C V2x 9150 FirmwareFastconnect 6800 Firmware+68 moreFeb 5, 2025 Feb 3, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure during audio playback. |
1Qualcomm 28Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQam8295p Firmware+25 moreFeb 5, 2025 Feb 3, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure while processing information on firmware image during core initialization. |
1Qualcomm 182Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+179 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
1Qualcomm 41Msm8996au Firmware Qam8255p FirmwareQam8295p Firmware+38 moreJan 13, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tamper...Show more |
1Qualcomm 125Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+122 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. |
1Qualcomm 76Ar8035 Firmware C V2x 9150 FirmwareCsrb31024 Firmware+73 moreAug 11, 2025 Jan 6, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
1Qualcomm 38Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQam8295p Firmware+35 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while invoking IOCTL calls to unmap the DMA buffers. |
1Qualcomm 34Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQam8295p Firmware+31 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |
1Qualcomm 123Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+120 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. |
1Qualcomm 323205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+320 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
1Qualcomm 55C V2x 9150 Firmware Fastconnect 6200 FirmwareFastconnect 6800 Firmware+52 moreDec 12, 2024 Dec 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption when multiple threads try to unregister the CVP buffer at the same time. |
1Qualcomm 208315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+205 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
1Qualcomm 50C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+47 moreDec 11, 2024 Dec 2, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. |
1Qualcomm 51C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 moreDec 11, 2024 Dec 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. |
1Qualcomm 84Apq8096au Firmware Ar8031 FirmwareAr8035 Firmware+81 moreNov 25, 2024 Nov 22, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Possible out of bound access in audio module due to lack of validation of user provided input. |
1Qualcomm 117Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+114 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during GNSS HAL process initialization. |
1Qualcomm 203205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+200 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing GPU page table switch. |
1Qualcomm 263205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+260 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing voice packet with arbitrary data received from ADSP. |