Qca6797aq Firmware
by Qualcomm
CVEs (337)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49838 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Information disclosure while parsing the OCI IE with invalid length. | ||
| CVE-2024-38408 | Hig | 0.53 | 8.2 | 0.00 | Nov 4, 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | ||
| CVE-2024-33073 | Hig | 0.53 | 8.2 | 0.00 | Oct 7, 2024 | Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | ||
| CVE-2023-28585 | Hig | 0.53 | 8.2 | 0.00 | Dec 5, 2023 | Memory corruption while loading an ELF segment in TEE Kernel. | ||
| CVE-2023-28545 | Hig | 0.53 | 8.2 | 0.00 | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. | ||
| CVE-2025-47357 | Hig | 0.52 | 8.0 | 0.00 | Nov 4, 2025 | Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions. | ||
| CVE-2026-21366 | Hig | 0.51 | 7.8 | 0.00 | Aug 4, 2026 | Memory corruption while processing a packet with a size close to the maximum allowed value. | ||
| CVE-2025-59606 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | ||
| CVE-2025-59605 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. | ||
| CVE-2025-59604 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | ||
| CVE-2026-24082 | Hig | 0.51 | 7.8 | 0.00 | May 4, 2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. | ||
| CVE-2025-47391 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption while processing a frame request from user. | ||
| CVE-2025-47389 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | ||
| CVE-2025-47386 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | ||
| CVE-2025-47385 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | ||
| CVE-2025-47379 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | ||
| CVE-2025-47377 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | ||
| CVE-2025-47376 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | ||
| CVE-2025-47375 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | ||
| CVE-2025-47373 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. |
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the OCI IE with invalid length.
- risk 0.53cvss 8.2epss 0.00
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
- risk 0.53cvss 8.2epss 0.00
Memory corruption while loading an ELF segment in TEE Kernel.
- risk 0.53cvss 8.2epss 0.00
Memory corruption in TZ Secure OS while loading an app ELF.
- risk 0.52cvss 8.0epss 0.00
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a packet with a size close to the maximum allowed value.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a frame request from user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing trusted execution environment without proper privilege check.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing buffers with invalid length during TA invocation.
Page 5 of 17