Wcd9385 Firmware
by Qualcomm
CVEs (1,105)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1910 | Hig | 0.47 | 7.3 | 0.01 | May 7, 2021 | Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2020-11252 | Hig | 0.47 | 7.2 | 0.00 | Apr 7, 2021 | Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2026-24090 | Hig | 0.46 | 7.1 | 0.00 | Jun 1, 2026 | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | ||
| CVE-2025-47378 | Hig | 0.46 | 7.1 | 0.00 | Mar 2, 2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | ||
| CVE-2025-47366 | Hig | 0.46 | 7.1 | 0.00 | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | ||
| CVE-2025-21482 | Hig | 0.46 | 7.1 | 0.00 | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2024-43065 | Hig | 0.46 | 7.1 | 0.00 | Apr 7, 2025 | Cryptographic issues while generating an asymmetric key pair for RKP use cases. | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. | ||
| CVE-2024-21462 | Hig | 0.46 | 7.1 | 0.00 | Jul 1, 2024 | Transient DOS while loading the TA ELF file. | ||
| CVE-2024-21460 | Hig | 0.46 | 7.1 | 0.00 | Jul 1, 2024 | Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space. | ||
| CVE-2023-33060 | Hig | 0.46 | 7.1 | 0.00 | Feb 6, 2024 | Transient DOS in Core when DDR memory check is called while DDR is not initialized. | ||
| CVE-2023-33037 | Hig | 0.46 | 7.1 | 0.00 | Jan 2, 2024 | Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data. | ||
| CVE-2023-33036 | Hig | 0.46 | 7.1 | 0.00 | Jan 2, 2024 | Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | ||
| CVE-2023-33070 | Hig | 0.46 | 7.1 | 0.00 | Dec 5, 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. | ||
| CVE-2023-28556 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2023 | Cryptographic issue in HLOS during key management. | ||
| CVE-2023-21626 | Hig | 0.46 | 7.1 | 0.00 | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | ||
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2022-40523 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Information disclosure in Kernel due to indirect branch misprediction. | ||
| CVE-2022-22076 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
- risk 0.47cvss 7.3epss 0.01
Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.47cvss 7.2epss 0.00
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
- risk 0.46cvss 7.1epss 0.00
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while performing RSA PKCS padding decoding.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
- risk 0.46cvss 7.1epss 0.00
Transient DOS while loading the TA ELF file.
- risk 0.46cvss 7.1epss 0.00
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
- risk 0.46cvss 7.1epss 0.00
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
- risk 0.46cvss 7.1epss 0.00
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
- risk 0.46cvss 7.1epss 0.00
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS during key management.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
Information disclosure in Kernel due to indirect branch misprediction.
- risk 0.46cvss 7.1epss 0.00
information disclosure due to cryptographic issue in Core during RPMB read request.
Page 45 of 56