Sm4635 Firmware
by Qualcomm
CVEs (77)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45553 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | ||
| CVE-2024-43048 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. | ||
| CVE-2024-38424 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption during GNSS HAL process initialization. | ||
| CVE-2024-38422 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | ||
| CVE-2024-38421 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU commands. | ||
| CVE-2024-38419 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | ||
| CVE-2024-23369 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. | ||
| CVE-2024-45549 | Hig | 0.50 | 7.7 | 0.00 | Apr 7, 2025 | Information disclosure while creating MQ channels. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2024-33058 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-33050 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | ||
| CVE-2025-47366 | Hig | 0.46 | 7.1 | 0.00 | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | ||
| CVE-2025-21482 | Hig | 0.46 | 7.1 | 0.00 | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2024-43065 | Hig | 0.46 | 7.1 | 0.00 | Apr 7, 2025 | Cryptographic issues while generating an asymmetric key pair for RKP use cases. | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during GNSS HAL process initialization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
- risk 0.50cvss 7.7epss 0.00
Information disclosure while creating MQ channels.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while performing RSA PKCS padding decoding.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
Page 3 of 4