Msm8996au Firmware
by Qualcomm
CVEs (678)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21484 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | ||
| CVE-2025-21427 | Hig | 0.53 | 8.2 | 0.00 | Jul 8, 2025 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | ||
| CVE-2024-53026 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | ||
| CVE-2024-53020 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | ||
| CVE-2024-45552 | Hig | 0.53 | 8.2 | 0.00 | Apr 7, 2025 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | ||
| CVE-2023-43555 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2024 | Information disclosure in Video while parsing mp2 clip with invalid section length. | ||
| CVE-2023-24849 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | ||
| CVE-2023-24848 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | ||
| CVE-2023-22385 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | ||
| CVE-2022-40503 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | ||
| CVE-2022-33271 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure due to buffer over-read in WLAN while parsing NMF frame. | ||
| CVE-2022-33235 | Hig | 0.53 | 8.2 | 0.00 | Dec 13, 2022 | Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2022-25706 | Hig | 0.53 | 8.2 | 0.00 | Sep 16, 2022 | Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-22062 | Hig | 0.53 | 8.2 | 0.00 | Sep 2, 2022 | An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… | ||
| CVE-2021-35083 | Hig | 0.53 | 8.2 | 0.00 | Jun 14, 2022 | Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2021-35117 | Hig | 0.53 | 8.2 | 0.01 | Apr 1, 2022 | An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2020-11285 | Hig | 0.53 | 8.2 | 0.01 | May 7, 2021 | Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2020-11251 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2021 | Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2020-11191 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2021 | Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2019-10494 | Hig | 0.53 | 8.1 | 0.00 | Dec 12, 2019 | Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… |
- risk 0.53cvss 8.2epss 0.00
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Video while parsing mp2 clip with invalid section length.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- risk 0.53cvss 8.2epss 0.00
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.53cvss 8.2epss 0.00
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
- risk 0.53cvss 8.2epss 0.00
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.53cvss 8.2epss 0.01
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.53cvss 8.2epss 0.01
Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
- risk 0.53cvss 8.2epss 0.01
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
- risk 0.53cvss 8.2epss 0.01
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.53cvss 8.1epss 0.00
Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
Page 13 of 34