Sm6475 Firmware
by Qualcomm
CVEs (18)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27038 | Hig | 0.61 | 7.5 | 0.01 | KEV | Jun 3, 2025 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | |
| CVE-2025-47345 | Hig | 0.55 | 8.4 | 0.00 | Jan 7, 2026 | Cryptographic issue may occur while encrypting license data. | ||
| CVE-2025-47396 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption occurs when a secure application is launched on a device with insufficient memory. | ||
| CVE-2025-47394 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. | ||
| CVE-2025-47388 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while passing pages to DSP with an unaligned starting address. | ||
| CVE-2025-47348 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing identity credential operations in the trusted application. | ||
| CVE-2025-47346 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing a secure logging command in the trusted application. | ||
| CVE-2025-47339 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. | ||
| CVE-2025-47323 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while routing GPR packets between user and root when handling large data packet. | ||
| CVE-2025-47321 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while copying packets received from unix clients. | ||
| CVE-2025-47354 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while allocating buffers in DSP service. | ||
| CVE-2025-47317 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption due to global buffer overflow when a test command uses an invalid payload type. | ||
| CVE-2025-47366 | Hig | 0.46 | 7.1 | 0.00 | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | ||
| CVE-2025-47334 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. | ||
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. |
- risk 0.61cvss 7.5epss 0.01
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
- risk 0.55cvss 8.4epss 0.00
Cryptographic issue may occur while encrypting license data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing pages to DSP with an unaligned starting address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing identity credential operations in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a secure logging command in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while deinitializing a HDCP session.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while routing GPR packets between user and root when handling large data packet.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying packets received from unix clients.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while allocating buffers in DSP service.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.