Wcd9340 Firmware
by Qualcomm
CVEs (769)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2025-27041 | Med | 0.36 | 5.5 | 0.00 | Oct 9, 2025 | Transient DOS while processing video packets received from video firmware. | ||
| CVE-2024-43046 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. | ||
| CVE-2024-43056 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2024-33043 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | ||
| CVE-2023-33111 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2024 | Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. | ||
| CVE-2023-33090 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing channel information for speaker protection v2 module in ADSP. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. | ||
| CVE-2022-25675 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2022 | Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-25663 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity | ||
| CVE-2021-35119 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11265 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2021 | Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking | ||
| CVE-2020-11221 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2021 | Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… | ||
| CVE-2020-11199 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2021 | HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2024-38426 | Med | 0.35 | 5.4 | 0.00 | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | ||
| CVE-2024-53009 | Med | 0.34 | 5.3 | 0.00 | Jul 8, 2025 | Memory corruption while operating the mailbox in Automotive. | ||
| CVE-2022-25662 | Med | 0.34 | 5.3 | 0.00 | Oct 19, 2022 | Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1903 | Med | 0.34 | 5.3 | 0.01 | Nov 12, 2021 | Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… | ||
| CVE-2021-1967 | Med | 0.34 | 5.3 | 0.00 | Oct 20, 2021 | Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN Match event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing video packets received from video firmware.
- risk 0.36cvss 5.5epss 0.00
There may be information disclosure during memory re-allocation in TZ Secure OS.
- risk 0.36cvss 5.5epss 0.00
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
- risk 0.36cvss 5.5epss 0.00
Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.36cvss 5.5epss 0.00
Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity
- risk 0.36cvss 5.5epss 0.00
Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.36cvss 5.5epss 0.00
Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking
- risk 0.36cvss 5.5epss 0.00
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…
- risk 0.36cvss 5.5epss 0.00
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.35cvss 5.4epss 0.00
While processing the authentication message in UE, improper authentication may lead to information disclosure.
- risk 0.34cvss 5.3epss 0.00
Memory corruption while operating the mailbox in Automotive.
- risk 0.34cvss 5.3epss 0.00
Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.34cvss 5.3epss 0.01
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
- risk 0.34cvss 5.3epss 0.00
Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN Match event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
Page 38 of 39