Wcn3988 Firmware
by Qualcomm
CVEs (899)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11290 | Hig | 0.46 | 7.0 | 0.00 | Mar 17, 2021 | Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2020-11203 | Hig | 0.46 | 7.1 | 0.00 | Feb 22, 2021 | Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2025-59613 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. | ||
| CVE-2025-47344 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while handling sensor utility operations. | ||
| CVE-2025-47334 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. | ||
| CVE-2025-47332 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while processing a config call from userspace. | ||
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2024-49848 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | Memory corruption while processing multiple IOCTL calls from HLOS to DSP. | ||
| CVE-2024-33061 | Med | 0.44 | 6.8 | 0.00 | Jan 6, 2025 | Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process. | ||
| CVE-2024-33053 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when multiple threads try to unregister the CVP buffer at the same time. | ||
| CVE-2024-33040 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access. | ||
| CVE-2024-33039 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service. | ||
| CVE-2024-33036 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | ||
| CVE-2021-30299 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. | ||
| CVE-2024-33032 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. | ||
| CVE-2024-23376 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. | ||
| CVE-2024-23375 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption during the network scan request. | ||
| CVE-2024-23374 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. | ||
| CVE-2024-23370 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. |
- risk 0.46cvss 7.0epss 0.00
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.46cvss 7.1epss 0.00
Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while handling sensor utility operations.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing a config call from userspace.
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
- risk 0.44cvss 6.8epss 0.00
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- risk 0.44cvss 6.7epss 0.00
Possible out of bound access in audio module due to lack of validation of user provided input.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.
- risk 0.44cvss 6.7epss 0.00
Memory corruption during the network scan request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
Page 36 of 45