Cologne Firmware
by Qualcomm
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47399 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. | ||
| CVE-2025-47356 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory Corruption when multiple threads concurrently access and modify shared resources. | ||
| CVE-2025-47343 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing a video session to set video parameters. | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2026-21367 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | ||
| CVE-2026-25288 | Hig | 0.48 | 7.4 | 0.00 | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||
| CVE-2026-24092 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory Corruption when processing fastboot commands to set display mode. | ||
| CVE-2026-24091 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory corruption while processing fastboot commands with improperly formatted input. | ||
| CVE-2026-24089 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory corruption while processing fastboot commands with invalid input. | ||
| CVE-2026-24087 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory corruption while processing fastboot OEM commands. | ||
| CVE-2026-24085 | Hig | 0.47 | 7.2 | 0.00 | Jun 1, 2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | ||
| CVE-2026-24090 | Hig | 0.46 | 7.1 | 0.00 | Jun 1, 2026 | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | ||
| CVE-2025-47378 | Hig | 0.46 | 7.1 | 0.00 | Mar 2, 2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | ||
| CVE-2026-24076 | Med | 0.44 | 6.7 | 0.00 | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | ||
| CVE-2025-59614 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. | ||
| CVE-2025-59613 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. | ||
| CVE-2025-59612 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory corruption in windows drivers while sending incorrect trusted application request | ||
| CVE-2025-59611 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when multiple threads concurrently access and modify shared resources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a video session to set video parameters.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- risk 0.48cvss 7.4epss 0.00
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- risk 0.47cvss 7.2epss 0.00
Memory Corruption when processing fastboot commands to set display mode.
- risk 0.47cvss 7.2epss 0.00
Memory corruption while processing fastboot commands with improperly formatted input.
- risk 0.47cvss 7.2epss 0.00
Memory corruption while processing fastboot commands with invalid input.
- risk 0.47cvss 7.2epss 0.00
Memory corruption while processing fastboot OEM commands.
- risk 0.47cvss 7.2epss 0.00
Memory Corruption when processing display command line information due to improper initialization of a variable.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
- risk 0.46cvss 7.1epss 0.00
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when processing registry values with incorrect types using a direct query method.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when sending random number generator command with insufficient output buffer size.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in windows drivers while sending incorrect trusted application request
- risk 0.44cvss 6.7epss 0.00
Memory corruption in diagnostic services due to absence of input validation
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
Page 2 of 3