Msm8996au Firmware
by Qualcomm
CVEs (707)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11258 | Hig | 0.51 | 7.8 | 0.00 | Jul 6, 2018 | In ADSP RPC in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, a Use After Free condition can occur in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD… | ||
| CVE-2021-35116 | Hig | 0.50 | 7.7 | 0.00 | Jun 14, 2022 | APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2018-11259 | Hig | 0.50 | 7.7 | 0.00 | Jul 6, 2018 | Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the… | ||
| CVE-2025-47318 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2025-21429 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | ||
| CVE-2025-21428 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-33051 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-23353 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33080 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2023-33020 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. | ||
| CVE-2023-33019 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2022-33213 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet | ||
| CVE-2022-40512 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. | ||
| CVE-2022-33299 | Hig | 0.49 | 7.5 | 0.00 | Jan 9, 2023 | Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. |
- risk 0.51cvss 7.8epss 0.00
In ADSP RPC in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, a Use After Free condition can occur in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD…
- risk 0.50cvss 7.7epss 0.00
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.50cvss 7.7epss 0.00
Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the EPTM test control message to get the test pattern.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.00
Memory corruption in modem due to buffer overflow while processing a PPP packet
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.
Page 26 of 36