CVEs (263)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 118Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+115 moreAug 11, 2025 Oct 7, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
1Qualcomm 163Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+160 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call for getting group info. |
1Qualcomm 243215 Mobile Firmware 315 5g Iot FirmwareAqt1000 Firmware+240 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when two threads try to map and unmap a single node simultaneously. |
1Qualcomm 170Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+167 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
1Qualcomm 197205 Mobile Firmware 215 Mobile FirmwareApq8017 Firmware+194 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when user provides data for FM HCI command control operations. |
1Qualcomm 282315 5g Iot Firmware 9206 Lte FirmwareApq8017 Firmware+279 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
1Qualcomm 252Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+249 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
1Qualcomm 187Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+184 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
1Qualcomm 175Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+172 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
1Qualcomm 197205 Mobile Platform Firmware 215 Mobile Platform FirmwareApq8017 Firmware+194 moreDec 20, 2024 Sep 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
1Qualcomm 196205 Firmware 215 FirmwareApq8017 Firmware+193 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when Alternative Frequency offset value is set to 255. |
1Qualcomm 89Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6800 Firmware+86 moreOct 3, 2025 Sep 2, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. |
1Qualcomm 331315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+328 moreOct 3, 2025 Sep 2, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 memory corruption when an invalid firehose patch command is invoked. |
1Qualcomm 47Fastconnect 7800 Firmware Qam8255p FirmwareQam8650p Firmware+44 moreOct 3, 2025 Sep 2, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Memory corruption while releasing shared resources in MinkSocket listener thread. |
1Qualcomm 177Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+174 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). |
1Qualcomm 2309205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+227 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Cryptographic issue while parsing RSA keys in COBR format. |
1Qualcomm 102Fastconnect 6200 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+99 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. |
1Qualcomm 164Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+161 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. |
1Qualcomm 167Csr8811 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+164 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |