Sm6250p Firmware
by Qualcomm
CVEs (235)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-3632 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2020 | u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P,… | ||
| CVE-2020-11207 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2020 | Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655,… | ||
| CVE-2020-11206 | Hig | 0.51 | 7.8 | 0.02 | Nov 12, 2020 | Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MSM8998, QCM4290, QCM6125, QCS410,… | ||
| CVE-2020-11201 | Hig | 0.51 | 7.8 | 0.02 | Nov 12, 2020 | Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P,… | ||
| CVE-2020-11127 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2020 | u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validation of security metadata while processing objects to be loaded' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2024-33051 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | ||
| CVE-2024-21477 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | ||
| CVE-2023-43529 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | ||
| CVE-2023-33086 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-43522 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33062 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. | ||
| CVE-2023-33040 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in Data Modem during DTLS handshake. | ||
| CVE-2023-21659 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem |
- risk 0.51cvss 7.8epss 0.00
u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P,…
- risk 0.51cvss 7.8epss 0.01
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655,…
- risk 0.51cvss 7.8epss 0.02
Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MSM8998, QCM4290, QCM6125, QCS410,…
- risk 0.51cvss 7.8epss 0.02
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P,…
- risk 0.51cvss 7.8epss 0.00
u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validation of security metadata while processing objects to be loaded' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a BTM request.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Data Modem during DTLS handshake.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing frames with missing header fields.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
Page 8 of 12