← Back

Sa8540p Firmware

sa8540p_firmware

Vendor: Qualcomm • 236 CVEs

CVEs (236)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
182Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+179 more
Aug 11, 2025
Jan 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
1Qualcomm
41Msm8996au Firmware
Qam8255p FirmwareQam8295p Firmware+38 more
Jan 13, 2025
Jan 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tamper...Show more
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.Show less
1Qualcomm
30Qam8255p Firmware
Qam8295p FirmwareQam8620p Firmware+27 more
Jan 13, 2025
Jan 6, 2025
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
1Qualcomm
17Qam8255p Firmware
Qam8295p FirmwareQam8650p Firmware+14 more
Jan 10, 2025
Jan 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
information disclosure while invoking the mailbox read API.
1Qualcomm
76Ar8035 Firmware
C V2x 9150 FirmwareCsrb31024 Firmware+73 more
Aug 11, 2025
Jan 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
1Qualcomm
17Qam8255p Firmware
Qam8295p FirmwareQam8650p Firmware+14 more
Jan 10, 2025
Jan 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
1Qualcomm
323205 Mobile Platform Firmware
315 5g Iot Modem Firmware9205 Lte Modem Firmware+320 more
Dec 12, 2024
Dec 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
1Qualcomm
55C V2x 9150 Firmware
Fastconnect 6200 FirmwareFastconnect 6800 Firmware+52 more
Dec 12, 2024
Dec 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
1Qualcomm
208315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+205 more
Dec 12, 2024
Dec 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
1Qualcomm
50C V2x 9150 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+47 more
Dec 11, 2024
Dec 2, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
1Qualcomm
51C V2x 9150 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 more
Dec 11, 2024
Dec 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
1Qualcomm
203205 Mobile Platform Firmware
215 Mobile Platform Firmware315 5g Iot Modem Firmware+200 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing GPU page table switch.
1Qualcomm
263205 Mobile Platform Firmware
215 Mobile Platform Firmware315 5g Iot Modem Firmware+260 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing voice packet with arbitrary data received from ADSP.
1Qualcomm
172215 Mobile Platform Firmware
Ar8035 FirmwareCsra6620 Firmware+169 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while handling session errors from firmware.
1Qualcomm
98Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+95 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Transient DOS while processing the CU information from RNR IE.
1Qualcomm
67C V2x 9150 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+64 more
Nov 7, 2024
Nov 4, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
1Qualcomm
44Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+41 more
Oct 16, 2024
Oct 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
1Qualcomm
131Csr8811 Firmware
Fastconnect 6700 FirmwareFastconnect 7800 Firmware+128 more
Aug 11, 2025
Oct 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
1Qualcomm
118Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+115 more
Aug 11, 2025
Oct 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
1Qualcomm
170Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+167 more
Aug 11, 2025
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.