← Back

Snapdragon X55 5g Firmware

snapdragon_x55_5g_firmware

Vendor: Qualcomm • 29 CVEs

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
233215 Firmware
315 5g Iot Modem FirmwareAqt1000 Firmware+230 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while calling the NPU driver APIs concurrently.
1Qualcomm
206205 Firmware
Apq8017 FirmwareAr8035 Firmware+203 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS may occur while processing the country IE.
1Qualcomm
244215 Firmware
315 5g Iot Modem FirmwareAqt1000 Firmware+241 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occur while validating ports and channels in Audio driver.
1Qualcomm
151Ar8035 Firmware
C V2x 9150 FirmwareCsr8811 Firmware+148 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing command in Glink linux.
1Qualcomm
187Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+184 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
1Qualcomm
237Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+234 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure while deriving keys for a session for any Widevine use case.
1Qualcomm
163Apq8064au Firmware
Aqt1000 FirmwareAr8035 Firmware+160 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Graphics while processing user packets for command submission.
1Qualcomm
190315 5g Firmware
Aqt1000 FirmwareAr8035 Firmware+187 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
1Qualcomm
195315 5g Iot Firmware
Aqt1000 FirmwareAr8035 Firmware+192 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while parsing WMI command parameters.
1Qualcomm
285315 5g Iot Firmware
Aqt1000 FirmwareAr8031 Firmware+282 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command through WMI interfaces.
1Qualcomm
2929205 Lte Firmware
Apq8017 FirmwareApq8064au Firmware+289 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
1Qualcomm
66Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6800 Firmware+63 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory corruption while handling payloads from remote ESL.
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEAS...Show more
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.Show less
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), caus...Show more
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.Show less
1Qualcomm
59205 Firmware
215 FirmwareAqt1000 Firmware+56 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
1Qualcomm
183315 5g Iot Firmware
Apq8064au FirmwareAqt1000 Firmware+180 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN HOST while fetching TX status information.
1Qualcomm
198Aqt1000 Firmware
Ar8031 FirmwareAr9380 Firmware+195 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
1Qualcomm
158215 Firmware
Ar8035 FirmwareCsra6620 Firmware+155 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
1Qualcomm
186Ar8035 Firmware
Csr8811 FirmwareCsra6620 Firmware+183 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
1Qualcomm
200205 Firmware
215 Firmware315 5g Iot Firmware+197 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Audio while allocating the ion buffer during the music playback.