Qca6584au Firmware
by Qualcomm
CVEs (1,121)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-33296 | Med | 0.38 | 5.9 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | ||
| CVE-2022-33260 | Med | 0.38 | 5.9 | 0.00 | Mar 10, 2023 | Memory corruption due to stack based buffer overflow in core while sending command from USB of large size. | ||
| CVE-2022-33266 | Med | 0.38 | 5.9 | 0.00 | Jan 9, 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. | ||
| CVE-2020-11294 | Med | 0.38 | 5.9 | 0.00 | May 7, 2021 | Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2025-59609 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | ||
| CVE-2025-47369 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2025-27041 | Med | 0.36 | 5.5 | 0.00 | Oct 9, 2025 | Transient DOS while processing video packets received from video firmware. | ||
| CVE-2025-27072 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing a packet at EAVB BE side with invalid header length. | ||
| CVE-2025-21431 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | Information disclosure may be there when a guest VM is connected. | ||
| CVE-2024-43046 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. | ||
| CVE-2024-43056 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2024-33043 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | ||
| CVE-2023-33111 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2024 | Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. | ||
| CVE-2023-33090 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing channel information for speaker protection v2 module in ADSP. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. | ||
| CVE-2022-33303 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue. | ||
| CVE-2021-35119 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-35085 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
- risk 0.38cvss 5.9epss 0.00
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
- risk 0.38cvss 5.9epss 0.00
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
- risk 0.38cvss 5.9epss 0.00
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.
- risk 0.38cvss 5.9epss 0.00
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.36cvss 5.5epss 0.00
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing video packets received from video firmware.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while processing a packet at EAVB BE side with invalid header length.
- risk 0.36cvss 5.5epss 0.00
Information disclosure may be there when a guest VM is connected.
- risk 0.36cvss 5.5epss 0.00
There may be information disclosure during memory re-allocation in TZ Secure OS.
- risk 0.36cvss 5.5epss 0.00
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
- risk 0.36cvss 5.5epss 0.00
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.
- risk 0.36cvss 5.5epss 0.00
Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.36cvss 5.5epss 0.00
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Page 55 of 57