Sxr2250p Firmware
by Qualcomm
CVEs (191)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2024-33042 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. | ||
| CVE-2024-23356 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption during session sign renewal request calls in HLOS. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2024-45549 | Hig | 0.50 | 7.7 | 0.00 | Apr 7, 2025 | Information disclosure while creating MQ channels. | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2025-47318 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. | ||
| CVE-2025-27073 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while creating NDP instance. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-27065 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a frame with malformed shared-key descriptor. | ||
| CVE-2025-27057 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-21463 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. | ||
| CVE-2025-21459 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while parsing per STA profile in ML IE. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when Alternative Frequency offset value is set to 255.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during session sign renewal request calls in HLOS.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.50cvss 7.7epss 0.00
Information disclosure while creating MQ channels.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the EPTM test control message to get the test pattern.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while creating NDP instance.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a frame with malformed shared-key descriptor.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling beacon frames with invalid IE header length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the EHT operation IE in the received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing per STA profile in ML IE.
Page 5 of 10