Wcd9395 Firmware
by Qualcomm
CVEs (387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47318 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. | ||
| CVE-2025-27073 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while creating NDP instance. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-27065 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a frame with malformed shared-key descriptor. | ||
| CVE-2025-21477 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing CCCH data when NW sends data with invalid length. | ||
| CVE-2025-21452 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. | ||
| CVE-2025-27057 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-27029 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | ||
| CVE-2025-21463 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. | ||
| CVE-2025-21459 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while parsing per STA profile in ML IE. | ||
| CVE-2024-49847 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2025-21435 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. | ||
| CVE-2025-21434 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing EHT operation IE or EHT capability IE. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2025-21429 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | ||
| CVE-2024-33058 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-38404 | Hig | 0.49 | 7.5 | 0.00 | Feb 3, 2025 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the EPTM test control message to get the test pattern.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while creating NDP instance.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a frame with malformed shared-key descriptor.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing CCCH data when NW sends data with invalid length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling beacon frames with invalid IE header length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the EHT operation IE in the received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing per STA profile in ML IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing extended IE in beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- risk 0.49cvss 7.5epss 0.00
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Page 12 of 20