Snapdragon X35 5g Modem Rf System Firmware
snapdragon_x35_5g_modem-rf_system_firmware
Vendor: Qualcomm • 94 CVEs
CVEs (94)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 252Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+249 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
1Qualcomm 175Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+172 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
1Qualcomm 331315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+328 moreOct 3, 2025 Sep 2, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 memory corruption when an invalid firehose patch command is invoked. |
1Qualcomm 177Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+174 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA). |
1Qualcomm 2309205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+227 moreOct 3, 2025 Sep 2, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Cryptographic issue while parsing RSA keys in COBR format. |
1Qualcomm 159205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+156 moreOct 3, 2025 Sep 2, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released. |
1Qualcomm 123Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+120 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while allocating memory in HGSL driver. |
1Qualcomm 136Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+133 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call to set metainfo. |
1Qualcomm 319315 5g Iot Modem Firmware 860 Mobile Platform FirmwareApq8064au Firmware+316 moreNov 20, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
1Qualcomm 247Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
1Qualcomm 246Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+243 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
1Qualcomm 236215 Mobile Platform Firmware Apq8017 FirmwareApq8037 Firmware+233 moreNov 25, 2024 Aug 5, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
1Qualcomm 208Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+205 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during session sign renewal request calls in HLOS. |
1Qualcomm 141Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+138 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when keymaster operation imports a shared key. |
1Qualcomm 247205 Mobile Platform Firmware 215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
1Qualcomm 103315 5g Iot Modem Firmware Ar8035 FirmwareFastconnect 6200 Firmware+100 moreNov 26, 2024 Aug 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. |
1Qualcomm 25Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+22 moreNov 26, 2024 Aug 5, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network. |
1Qualcomm 165Aqt1000 Firmware Ar8035 FirmwareFastconnect 6200 Firmware+162 moreAug 11, 2025 Aug 5, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |