Snapdragon Ar2 Gen 1 Firmware
by Qualcomm
CVEs (72)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27061 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-53024 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption in display driver while detaching a device. | ||
| CVE-2024-53014 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while validating ports and channels in Audio driver. | ||
| CVE-2024-45580 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. | ||
| CVE-2024-49834 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. | ||
| CVE-2024-49833 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption can occur in the camera when an invalid CID is used. | ||
| CVE-2024-45553 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | ||
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-33038 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2023-43550 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2024 | Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. | ||
| CVE-2023-28573 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing WMI command parameters. | ||
| CVE-2023-28567 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in display driver while detaching a device.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while validating ports and channels in Audio driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while power-up or power-down sequence of the camera sensor.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur in the camera when an invalid CID is used.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing WMI command parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command through WMI interfaces.
Page 2 of 4