Ipq8064 Firmware
by Qualcomm
CVEs (187)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11871 | Hig | 0.51 | 7.8 | 0.00 | Oct 29, 2018 | Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU,… | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2024-33050 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-33012 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | ||
| CVE-2024-33011 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | ||
| CVE-2024-33010 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing fragments of MBSSID IE from beacon frame. | ||
| CVE-2023-33105 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43522 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33116 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. | ||
| CVE-2023-33109 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. | ||
| CVE-2023-33062 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. | ||
| CVE-2023-33098 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing WPA IES, when it is passed with length more than expected size. | ||
| CVE-2023-33089 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS when processing a NULL buffer while parsing WLAN vdev. | ||
| CVE-2023-33080 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | ||
| CVE-2023-33047 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing no-inherit IES. |
- risk 0.51cvss 7.8epss 0.00
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU,…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a BTM request.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing no-inherit IES.
Page 6 of 10