Qca6698aq Firmware
by Qualcomm
CVEs (523)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22668 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Audio while invoking IOCTLs calls from the user-space. | ||
| CVE-2023-21633 | Med | 0.44 | 6.7 | 0.00 | Jul 4, 2023 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | ||
| CVE-2023-21629 | Med | 0.44 | 6.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | ||
| CVE-2022-33263 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to use after free in Core when multiple DCI clients register and deregister. | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33226 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications. | ||
| CVE-2022-33224 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2024-53013 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing voice call registration with user. | ||
| CVE-2024-49830 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while processing an IOCTL call to set mixer controls. | ||
| CVE-2024-45581 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while sound model registration for voice activation with audio kernel driver. | ||
| CVE-2024-45562 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. | ||
| CVE-2024-45544 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while processing IOCTL calls to add route entry in the HW. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2024-23366 | Med | 0.43 | 6.6 | 0.00 | Jan 6, 2025 | Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size. | ||
| CVE-2023-28572 | Med | 0.43 | 6.6 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN HOST while processing the WLAN scan descriptor list. | ||
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. |
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
- risk 0.44cvss 6.8epss 0.00
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in Core when multiple DCI clients register and deregister.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing voice call registration with user.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing an IOCTL call to set mixer controls.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while sound model registration for voice activation with audio kernel driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption during concurrent access to server info object due to unprotected critical field.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL calls to add route entry in the HW.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.43cvss 6.6epss 0.00
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Page 23 of 27