Wcd9375 Firmware
by Qualcomm
CVEs (944)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35071 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,… | ||
| CVE-2021-30331 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2022 | Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1930 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2021 | Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11221 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2021 | Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… | ||
| CVE-2020-11199 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2021 | HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2024-38426 | Med | 0.35 | 5.4 | 0.00 | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | ||
| CVE-2024-53009 | Med | 0.34 | 5.3 | 0.00 | Jul 8, 2025 | Memory corruption while operating the mailbox in Automotive. | ||
| CVE-2022-25662 | Med | 0.34 | 5.3 | 0.00 | Oct 19, 2022 | Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1903 | Med | 0.34 | 5.3 | 0.01 | Nov 12, 2021 | Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… | ||
| CVE-2021-1967 | Med | 0.34 | 5.3 | 0.00 | Oct 20, 2021 | Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN Match event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2020-11293 | Med | 0.33 | 5.1 | 0.00 | May 7, 2021 | Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… | ||
| CVE-2021-1901 | Med | 0.30 | 4.6 | 0.00 | Jul 13, 2021 | Possible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-1899 | Med | 0.30 | 4.6 | 0.00 | Jul 13, 2021 | Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1898 | Med | 0.30 | 4.6 | 0.00 | Jul 13, 2021 | Possible buffer over-read due to incorrect overflow check when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-1897 | Med | 0.30 | 4.6 | 0.00 | Jul 13, 2021 | Possible Buffer Over-read due to lack of validation of boundary checks when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2026-25268 | Hig | 0.00 | 8.8 | 0.00 | Jul 6, 2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | ||
| CVE-2026-21384 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | ||
| CVE-2026-21379 | Hig | 0.00 | 7.8 | 0.00 | Jul 6, 2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | ||
| CVE-2026-21370 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | ||
| CVE-2026-21369 | Med | 0.00 | 5.3 | 0.00 | Jul 6, 2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. |
- risk 0.36cvss 5.5epss 0.00
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,…
- risk 0.36cvss 5.5epss 0.00
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.36cvss 5.5epss 0.00
Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.36cvss 5.5epss 0.00
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…
- risk 0.36cvss 5.5epss 0.00
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.35cvss 5.4epss 0.00
While processing the authentication message in UE, improper authentication may lead to information disclosure.
- risk 0.34cvss 5.3epss 0.00
Memory corruption while operating the mailbox in Automotive.
- risk 0.34cvss 5.3epss 0.00
Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.34cvss 5.3epss 0.01
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
- risk 0.34cvss 5.3epss 0.00
Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN Match event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.33cvss 5.1epss 0.00
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
- risk 0.30cvss 4.6epss 0.00
Possible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.30cvss 4.6epss 0.00
Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.30cvss 4.6epss 0.00
Possible buffer over-read due to incorrect overflow check when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.30cvss 4.6epss 0.00
Possible Buffer Over-read due to lack of validation of boundary checks when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.00cvss 8.8epss 0.00
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
- risk 0.00cvss 7.8epss 0.00
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
- risk 0.00cvss 5.3epss 0.00
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Page 47 of 48