Qualcomm
by Qualcomm
CVEs (55)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47315 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while handling repeated memory unmap requests from guest VM. | ||
| CVE-2025-27068 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing an IOCTL command with an arbitrary address. | ||
| CVE-2025-27062 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | ||
| CVE-2025-21456 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently. | ||
| CVE-2025-27044 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while executing timestamp video decode command with large input values. | ||
| CVE-2025-21486 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. | ||
| CVE-2025-21437 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing memory map or unmap IOCTL operations simultaneously. | ||
| CVE-2025-21423 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption occurs when handling client calls to EnableTestMode through an Escape call. | ||
| CVE-2024-53029 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53022 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during communication between primary and guest VM. | ||
| CVE-2024-45580 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. | ||
| CVE-2024-43061 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive. | ||
| CVE-2024-45561 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while handling IOCTL call from user-space to set latency level. | ||
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-45558 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | ||
| CVE-2023-43529 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | ||
| CVE-2026-25288 | Hig | 0.48 | 7.4 | 0.00 | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||
| CVE-2025-47400 | Hig | 0.46 | 7.1 | 0.00 | Apr 6, 2026 | Cryptographic issue while copying data to a destination buffer without validating its size. | ||
| CVE-2025-21482 | Hig | 0.46 | 7.1 | 0.00 | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling repeated memory unmap requests from guest VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing an IOCTL command with an arbitrary address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling client exceptions, allowing unauthorized channel access.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while executing timestamp video decode command with large input values.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing memory map or unmap IOCTL operations simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during communication between primary and guest VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL call from user-space to set latency level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.49cvss 7.5epss 0.00
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
- risk 0.48cvss 7.4epss 0.00
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while copying data to a destination buffer without validating its size.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while performing RSA PKCS padding decoding.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Page 2 of 3