Wcd9375 Firmware
by Qualcomm
CVEs (944)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27043 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing manipulated payload in video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21466 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing a private escape command in an event trigger. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-27031 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed. | ||
| CVE-2024-53010 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. | ||
| CVE-2025-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing escape code, when DisplayId is passed with large unsigned value. | ||
| CVE-2025-21470 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. | ||
| CVE-2025-21469 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2025-21467 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-49835 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading secure file. | ||
| CVE-2025-21441 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | ||
| CVE-2025-21440 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | ||
| CVE-2025-21439 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing manipulated payload in video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a private escape command in an event trigger.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading the FW response from the shared queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading secure file.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.
Page 19 of 48