Qcs8250 Firmware
by Qualcomm
CVEs (180)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33033 | Hig | 0.55 | 8.4 | 0.00 | Jan 2, 2024 | Memory corruption in Audio during playback with speaker protection. | ||
| CVE-2023-33092 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. | ||
| CVE-2023-33088 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption when processing cmd parameters while parsing vdev. | ||
| CVE-2023-24852 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Memory Corruption in Core due to secure memory access by user while loading modem image. | ||
| CVE-2023-33029 | Hig | 0.55 | 8.4 | 0.00 | Oct 3, 2023 | Memory corruption in DSP Service during a remote call from HLOS to DSP. | ||
| CVE-2022-33275 | Hig | 0.55 | 8.4 | 0.00 | Sep 5, 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. | ||
| CVE-2023-22667 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | ||
| CVE-2023-21666 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | ||
| CVE-2023-21665 | Hig | 0.55 | 8.4 | 0.00 | May 2, 2023 | Memory corruption in Graphics while importing a file. | ||
| CVE-2024-49839 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. | ||
| CVE-2024-49838 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Information disclosure while parsing the OCI IE with invalid length. | ||
| CVE-2024-38408 | Hig | 0.53 | 8.2 | 0.00 | Nov 4, 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | ||
| CVE-2024-33073 | Hig | 0.53 | 8.2 | 0.00 | Oct 7, 2024 | Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | ||
| CVE-2023-43555 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2024 | Information disclosure in Video while parsing mp2 clip with invalid section length. | ||
| CVE-2023-28585 | Hig | 0.53 | 8.2 | 0.00 | Dec 5, 2023 | Memory corruption while loading an ELF segment in TEE Kernel. | ||
| CVE-2023-28545 | Hig | 0.53 | 8.2 | 0.00 | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. | ||
| CVE-2023-21669 | Hig | 0.53 | 8.2 | 0.00 | Jun 6, 2023 | Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address. | ||
| CVE-2025-47322 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while handling IOCTL calls to set mode. | ||
| CVE-2025-47320 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while processing MFC channel configuration during music playback. | ||
| CVE-2025-27063 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption during video playback when video session open fails with time out error. |
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio during playback with speaker protection.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when processing cmd parameters while parsing vdev.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Core due to secure memory access by user while loading modem image.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in DSP Service during a remote call from HLOS to DSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while allocating the ion buffer during the music playback.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Graphics while importing a file.
- risk 0.53cvss 8.2epss 0.00
Memory corruption during management frame processing due to mismatch in T2LM info element.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the OCI IE with invalid length.
- risk 0.53cvss 8.2epss 0.00
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Video while parsing mp2 clip with invalid section length.
- risk 0.53cvss 8.2epss 0.00
Memory corruption while loading an ELF segment in TEE Kernel.
- risk 0.53cvss 8.2epss 0.00
Memory corruption in TZ Secure OS while loading an app ELF.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL calls to set mode.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing MFC channel configuration during music playback.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during video playback when video session open fails with time out error.
Page 3 of 9