Wcd9395 Firmware
by Qualcomm
CVEs (387)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33041 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | ||
| CVE-2024-33033 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while processing IOCTL calls to unmap the buffers. | ||
| CVE-2024-23377 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2024-53015 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. | ||
| CVE-2024-45583 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations. | ||
| CVE-2024-38413 | Med | 0.43 | 6.6 | 0.00 | Feb 3, 2025 | Memory corruption while processing frame packets. | ||
| CVE-2024-38412 | Med | 0.43 | 6.6 | 0.00 | Feb 3, 2025 | Memory corruption while invoking IOCTL calls from user-space to kernel-space to handle session errors. | ||
| CVE-2024-38411 | Med | 0.43 | 6.6 | 0.00 | Feb 3, 2025 | Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||
| CVE-2026-24077 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-47371 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | ||
| CVE-2025-47402 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. | ||
| CVE-2025-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing IOCTL calls to unmap the buffers.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL command to handle buffers associated with a session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing frame packets.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL calls from user-space to kernel-space to handle session errors.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a received frame with an excessively large authentication information element.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
Page 18 of 20