CVEs (886)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 91205 Mobile Platform Firmware Apq8017 FirmwareApq8037 Firmware+88 moreNov 7, 2024 Nov 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. |
1Qualcomm 62Fastconnect 6700 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+59 moreOct 28, 2025 Oct 7, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while maintaining memory maps of HLOS memory. |
1Qualcomm 44Fastconnect 6800 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+41 moreOct 16, 2024 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host. |
1Qualcomm 131Csr8811 Firmware Fastconnect 6700 FirmwareFastconnect 7800 Firmware+128 moreAug 11, 2025 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. |
1Qualcomm 21Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQca6174a Firmware+18 moreOct 16, 2024 Oct 7, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. |
1Qualcomm 14Sa4150p Firmware Sa4155p FirmwareSa6155p Firmware+11 moreOct 16, 2024 Oct 7, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption during the network scan request. |
1Qualcomm 26Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQca6174a Firmware+23 moreOct 16, 2024 Oct 7, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. |
1Qualcomm 11Qca6584au Firmware Qca6698aq FirmwareQca9367 Firmware+8 moreOct 16, 2024 Oct 7, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. |
1Qualcomm 118Ar8035 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+115 moreAug 11, 2025 Oct 7, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
1Qualcomm 163Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+160 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing IOCTL call for getting group info. |
1Qualcomm 40Ar8035 Firmware C V2x 9150 FirmwareFastconnect 7800 Firmware+37 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing concurrent IOCTL calls. |
1Qualcomm 243215 Mobile Firmware 315 5g Iot FirmwareAqt1000 Firmware+240 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when two threads try to map and unmap a single node simultaneously. |
1Qualcomm 197205 Mobile Firmware 215 Mobile FirmwareApq8017 Firmware+194 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when user provides data for FM HCI command control operations. |
1Qualcomm 282315 5g Iot Firmware 9206 Lte FirmwareApq8017 Firmware+279 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
1Qualcomm 252Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+249 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
1Qualcomm 187Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+184 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
1Qualcomm 175Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+172 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
1Qualcomm 197205 Mobile Platform Firmware 215 Mobile Platform FirmwareApq8017 Firmware+194 moreDec 20, 2024 Sep 2, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
1Qualcomm 196205 Firmware 215 FirmwareApq8017 Firmware+193 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when Alternative Frequency offset value is set to 255. |
1Qualcomm 43Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+40 moreAug 11, 2025 Sep 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |