← Back

Wcn3660b Firmware

wcn3660b_firmware

Vendor: Qualcomm • 548 CVEs

CVEs (548)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
239315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+236 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
1Qualcomm
163Apq8064au Firmware
Aqt1000 FirmwareAr8035 Firmware+160 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Graphics while processing user packets for command submission.
1Qualcomm
82205 Firmware
215 Firmware9206 Lte Firmware+79 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
1Qualcomm
82205 Firmware
215 Firmware9206 Lte Firmware+79 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
1Qualcomm
2929205 Lte Firmware
Apq8017 FirmwareApq8064au Firmware+289 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
1Qualcomm
2678098 Firmware
8998 FirmwareApq5053 Aa Firmware+264 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
1Qualcomm
43Qca6390 Firmware
Qca6391 FirmwareQca6426 Firmware+40 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
1Qualcomm
38Aqt1000 Firmware
Qca6420 FirmwareQca6430 Firmware+35 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption while accessing metadata in Display.
1Qualcomm
31Qca6391 Firmware
Qca6574au FirmwareQca6696 Firmware+28 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio while validating and mapping metadata.
1Qualcomm
56Apq8096au Firmware
Aqt1000 FirmwareMdm9150 Firmware+53 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Audio during playback session with audio effects enabled.
1Qualcomm
51Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+48 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
1Qualcomm
51Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+48 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption due to improper validation of array index in Linux while updating adn record.
1Qualcomm
38Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+35 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEAS...Show more
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel address.Show less
1Qualcomm
30Fastconnect 6800 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+27 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), caus...Show more
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.Show less
1Qualcomm
59205 Firmware
215 FirmwareAqt1000 Firmware+56 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
1Qualcomm
183315 5g Iot Modem Firmware
8098 Firmware8998 Firmware+180 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while allocating memory in COmxApeDec module in Audio.
1Qualcomm
172Apq8009 Firmware
Apq8017 FirmwareApq8096au Firmware+169 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Audio while playing amrwbplus clips with modified content.
1Qualcomm
51Aqt1000 Firmware
Csrb31024 FirmwareQam8295p Firmware+48 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
1Qualcomm
65Apq8096au Firmware
Aqt1000 FirmwareMdm9628 Firmware+62 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN while running doDriverCmd for an unspecific command.