Qca6698aq Firmware
by Qualcomm
CVEs (523)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2024-49848 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | Memory corruption while processing multiple IOCTL calls from HLOS to DSP. | ||
| CVE-2024-33030 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size. | ||
| CVE-2024-33029 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while handling the PDR in driver for getting the remote heap maps. | ||
| CVE-2024-23379 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario. | ||
| CVE-2024-23378 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record. | ||
| CVE-2024-23374 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. | ||
| CVE-2024-23370 | Med | 0.44 | 6.7 | 0.00 | Oct 7, 2024 | Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2023-43544 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption when IPC callback handle is used after it has been released during register callback by another thread. | ||
| CVE-2023-43543 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object. | ||
| CVE-2023-43525 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption while copying the sound model data from user to kernel buffer during sound model register. | ||
| CVE-2023-43524 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when the bandpass filter order received from AHAL is not within the expected range. | ||
| CVE-2023-43521 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when multiple listeners are being registered with the same file descriptor. | ||
| CVE-2023-33077 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. | ||
| CVE-2023-33069 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. | ||
| CVE-2023-33068 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. | ||
| CVE-2023-33067 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. | ||
| CVE-2023-33038 | Med | 0.44 | 6.7 | 0.00 | Jan 2, 2024 | Memory corruption while receiving a message in Bus Socket Transport Server. | ||
| CVE-2023-33024 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory corruption while sending SMS from AP firmware. |
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while handling the PDR in driver for getting the remote heap maps.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
- risk 0.44cvss 6.7epss 0.00
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple listeners are being registered with the same file descriptor.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in HLOS while converting from authorization token to HIDL vector.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing IIR config data from AFE calibration block.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while receiving a message in Bus Socket Transport Server.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending SMS from AP firmware.
Page 22 of 27