Qcn9074 Firmware
by Qualcomm
CVEs (207)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2025-27040 | Med | 0.42 | 6.5 | 0.00 | Oct 9, 2025 | Information disclosure may occur while processing the hypervisor log. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2024-45556 | Med | 0.42 | 6.5 | 0.00 | Apr 7, 2025 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | ||
| CVE-2024-21467 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon probe frame during scan entry generation in client side. | ||
| CVE-2024-21466 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information disclosure while parsing sub-IE length during new IE generation. | ||
| CVE-2024-21458 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information disclosure while handling SA query action frame. | ||
| CVE-2024-21457 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | INformation disclosure while handling Multi-link IE in beacon frame. | ||
| CVE-2023-43537 | Med | 0.42 | 6.5 | 0.00 | Jun 3, 2024 | Information disclosure while handling T2LM Action Frame in WLAN Host. | ||
| CVE-2023-28576 | Med | 0.42 | 6.4 | 0.00 | Aug 8, 2023 | The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.… | ||
| CVE-2021-1960 | Med | 0.42 | 6.5 | 0.00 | Sep 9, 2021 | Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2025-27064 | Med | 0.40 | 6.1 | 0.00 | Nov 4, 2025 | Information disclosure while registering commands from clients with diag through diagHal. | ||
| CVE-2025-27030 | Med | 0.40 | 6.1 | 0.00 | Sep 24, 2025 | information disclosure while invoking calibration data from user space to update firmware size. | ||
| CVE-2024-33067 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | ||
| CVE-2023-28563 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. | ||
| CVE-2023-28554 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | ||
| CVE-2023-28553 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2022-25722 | Med | 0.39 | 6.0 | 0.00 | Jan 9, 2023 | Information exposure in DSP services due to improper handling of freeing memory |
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.5epss 0.00
Information disclosure may occur while processing the hypervisor log.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.42cvss 6.5epss 0.00
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon probe frame during scan entry generation in client side.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while parsing sub-IE length during new IE generation.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling SA query action frame.
- risk 0.42cvss 6.5epss 0.00
INformation disclosure while handling Multi-link IE in beacon frame.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling T2LM Action Frame in WLAN Host.
- risk 0.42cvss 6.4epss 0.00
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.…
- risk 0.42cvss 6.5epss 0.00
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.40cvss 6.1epss 0.00
Information disclosure while registering commands from clients with diag through diagHal.
- risk 0.40cvss 6.1epss 0.00
information disclosure while invoking calibration data from user space to update firmware size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in IOE Firmware while handling WMI command.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in WLAN Host when processing WMI event command.
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.39cvss 6.0epss 0.00
Information exposure in DSP services due to improper handling of freeing memory
Page 10 of 11