Wcd9385 Firmware
by Qualcomm
CVEs (1,105)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11295 | Med | 0.44 | 6.8 | 0.00 | May 7, 2021 | Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11231 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2021 | Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11308 | Med | 0.44 | 6.8 | 0.00 | Mar 17, 2021 | Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2020-11198 | Med | 0.44 | 6.7 | 0.00 | Feb 22, 2021 | Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2020-11147 | Med | 0.44 | 6.7 | 0.00 | Feb 22, 2021 | Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2025-59617 | Med | 0.43 | 6.6 | 0.00 | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. | ||
| CVE-2025-59616 | Med | 0.43 | 6.6 | 0.00 | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. | ||
| CVE-2025-59615 | Med | 0.43 | 6.6 | 0.00 | Jul 6, 2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2025-27039 | Med | 0.43 | 6.6 | 0.00 | Oct 9, 2025 | Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request. | ||
| CVE-2025-21426 | Med | 0.43 | 6.6 | 0.00 | Jul 8, 2025 | Memory corruption while processing camera TPG write request. | ||
| CVE-2024-53018 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing the OIS packet parser. | ||
| CVE-2024-53016 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing I2C settings in Camera driver. | ||
| CVE-2024-53015 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. | ||
| CVE-2024-45570 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. | ||
| CVE-2024-45563 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session. | ||
| CVE-2024-45562 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. | ||
| CVE-2024-45543 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while accessing MSM channel map and mixer functions. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2024-38411 | Med | 0.43 | 6.6 | 0.00 | Feb 3, 2025 | Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls. |
- risk 0.44cvss 6.8epss 0.00
Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.44cvss 6.7epss 0.00
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.44cvss 6.8epss 0.00
Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.44cvss 6.7epss 0.00
Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.44cvss 6.7epss 0.00
Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.43cvss 6.6epss 0.00
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
- risk 0.43cvss 6.6epss 0.00
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
- risk 0.43cvss 6.6epss 0.00
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing camera TPG write request.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing the OIS packet parser.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing I2C settings in Camera driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL command to handle buffers associated with a session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption during concurrent access to server info object due to unprotected critical field.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while accessing MSM channel map and mixer functions.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.
Page 50 of 56