Wcn3950 Firmware
by Qualcomm
CVEs (904)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1891 | Hig | 0.55 | 8.4 | 0.00 | May 7, 2021 | A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2020-11284 | Hig | 0.55 | 8.4 | 0.00 | May 7, 2021 | Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusted source of input for secure boot loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2020-11246 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2021 | A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11245 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2021 | Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and… | ||
| CVE-2020-11242 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2021 | User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-11237 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2021 | Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile | ||
| CVE-2020-11234 | Hig | 0.55 | 8.4 | 0.00 | Apr 7, 2021 | When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,… | ||
| CVE-2026-24079 | Hig | 0.53 | 8.1 | 0.00 | Aug 4, 2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | ||
| CVE-2026-24088 | Hig | 0.53 | 8.2 | 0.00 | Jun 1, 2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | ||
| CVE-2025-21488 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. | ||
| CVE-2025-21487 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | ||
| CVE-2025-21484 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | ||
| CVE-2025-21427 | Hig | 0.53 | 8.2 | 0.00 | Jul 8, 2025 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | ||
| CVE-2024-53026 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | ||
| CVE-2024-53021 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while processing goodbye RTCP packet from network. | ||
| CVE-2024-53020 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | ||
| CVE-2024-53019 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. | ||
| CVE-2024-45552 | Hig | 0.53 | 8.2 | 0.00 | Apr 7, 2025 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | ||
| CVE-2024-49839 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. | ||
| CVE-2024-49838 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Information disclosure while parsing the OCI IE with invalid length. |
- risk 0.55cvss 8.4epss 0.00
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusted source of input for secure boot loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.55cvss 8.4epss 0.00
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.00
Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and…
- risk 0.55cvss 8.4epss 0.00
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.00
Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.00
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
- risk 0.53cvss 8.1epss 0.00
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
- risk 0.53cvss 8.2epss 0.00
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while processing goodbye RTCP packet from network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
- risk 0.53cvss 8.2epss 0.00
Memory corruption during management frame processing due to mismatch in T2LM info element.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the OCI IE with invalid length.
Page 13 of 46