Wcn3950 Firmware
by Qualcomm
CVEs (904)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21371 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | ||
| CVE-2025-47391 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption while processing a frame request from user. | ||
| CVE-2025-47389 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | ||
| CVE-2025-59600 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | ||
| CVE-2025-47386 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | ||
| CVE-2025-47385 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | ||
| CVE-2025-47379 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | ||
| CVE-2025-47377 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | ||
| CVE-2025-47376 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | ||
| CVE-2025-47375 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | ||
| CVE-2025-47373 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | ||
| CVE-2025-47398 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | ||
| CVE-2025-47397 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | ||
| CVE-2025-47396 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption occurs when a secure application is launched on a device with insufficient memory. | ||
| CVE-2025-47394 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. | ||
| CVE-2025-47388 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while passing pages to DSP with an unaligned starting address. | ||
| CVE-2025-47348 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing identity credential operations in the trusted application. | ||
| CVE-2025-47346 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing a secure logging command in the trusted application. | ||
| CVE-2025-47339 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while deinitializing a HDCP session. | ||
| CVE-2025-47382 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while loading an invalid firmware in boot loader. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when retrieving output buffer with insufficient size validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a frame request from user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when adding user-supplied data without checking available buffer space.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing trusted execution environment without proper privilege check.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing buffers with invalid length during TA invocation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing pages to DSP with an unaligned starting address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing identity credential operations in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a secure logging command in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while deinitializing a HDCP session.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while loading an invalid firmware in boot loader.
Page 16 of 46