Qca9994 Firmware
by Qualcomm
CVEs (146)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24088 | Hig | 0.53 | 8.2 | 0.00 | Jun 1, 2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | ||
| CVE-2022-33271 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure due to buffer over-read in WLAN while parsing NMF frame. | ||
| CVE-2022-33284 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while parsing BTM action frame. | ||
| CVE-2022-33283 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check. | ||
| CVE-2022-33252 | Hig | 0.53 | 8.2 | 0.00 | Jan 9, 2023 | Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame. | ||
| CVE-2022-33235 | Hig | 0.53 | 8.2 | 0.00 | Dec 13, 2022 | Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2021-35088 | Hig | 0.53 | 8.2 | 0.01 | Apr 1, 2022 | Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon… | ||
| CVE-2025-47339 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2023-28573 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing WMI command parameters. | ||
| CVE-2023-28567 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28565 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | ||
| CVE-2023-28564 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. | ||
| CVE-2023-28560 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | ||
| CVE-2023-28559 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28558 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN handler while processing PhyID in Tx status handler. | ||
| CVE-2023-28557 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28549 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | ||
| CVE-2023-28548 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | ||
| CVE-2023-28544 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. |
- risk 0.53cvss 8.2epss 0.00
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.53cvss 8.2epss 0.01
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon…
- risk 0.51cvss 7.8epss 0.00
Memory corruption while deinitializing a HDCP session.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing WMI command parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
Page 3 of 8