CVEs (236)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 182Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+179 moreAug 11, 2025 Jan 6, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
1Qualcomm 41Msm8996au Firmware Qam8255p FirmwareQam8295p Firmware+38 moreJan 13, 2025 Jan 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tamper...Show more |
1Qualcomm 30Qam8255p Firmware Qam8295p FirmwareQam8620p Firmware+27 moreJan 13, 2025 Jan 6, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. |
1Qualcomm 17Qam8255p Firmware Qam8295p FirmwareQam8650p Firmware+14 moreJan 10, 2025 Jan 6, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 information disclosure while invoking the mailbox read API. |
1Qualcomm 76Ar8035 Firmware C V2x 9150 FirmwareCsrb31024 Firmware+73 moreAug 11, 2025 Jan 6, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
1Qualcomm 17Qam8255p Firmware Qam8295p FirmwareQam8650p Firmware+14 moreJan 10, 2025 Jan 6, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size. |
1Qualcomm 323205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+320 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
1Qualcomm 55C V2x 9150 Firmware Fastconnect 6200 FirmwareFastconnect 6800 Firmware+52 moreDec 12, 2024 Dec 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption when multiple threads try to unregister the CVP buffer at the same time. |
1Qualcomm 208315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+205 moreDec 12, 2024 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
1Qualcomm 50C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+47 moreDec 11, 2024 Dec 2, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. |
1Qualcomm 51C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 moreDec 11, 2024 Dec 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. |
1Qualcomm 203205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+200 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing GPU page table switch. |
1Qualcomm 263205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+260 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing voice packet with arbitrary data received from ADSP. |
1Qualcomm 172215 Mobile Platform Firmware Ar8035 FirmwareCsra6620 Firmware+169 moreNov 7, 2024 Nov 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while handling session errors from firmware. |
1Qualcomm 98Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+95 moreNov 7, 2024 Nov 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS while processing the CU information from RNR IE. |
1Qualcomm 67C V2x 9150 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+64 moreNov 7, 2024 Nov 4, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. |
1Qualcomm 44Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+41 moreOct 16, 2024 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host. |
1Qualcomm 131Csr8811 Firmware Fastconnect 6700 FirmwareFastconnect 7800 Firmware+128 moreAug 11, 2025 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. |
1Qualcomm 118Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+115 moreAug 11, 2025 Oct 7, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
1Qualcomm 170Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+167 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |