X2000086 Firmware
by Qualcomm
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25260 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. | ||
| CVE-2026-25259 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory corruption while processing multiple IOCTL command for escape operations. | ||
| CVE-2026-25258 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory corruption while processing IOCTL calls for escape operations. | ||
| CVE-2025-59606 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | ||
| CVE-2025-59604 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | ||
| CVE-2026-21382 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when handling power management requests with improperly sized input/output buffers. | ||
| CVE-2026-21380 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. | ||
| CVE-2026-21378 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | ||
| CVE-2026-21376 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | ||
| CVE-2026-21375 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | ||
| CVE-2026-21374 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | ||
| CVE-2026-21373 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | ||
| CVE-2026-21372 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. | ||
| CVE-2026-21371 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | ||
| CVE-2025-47390 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption while preprocessing IOCTL request in JPEG driver. | ||
| CVE-2025-47389 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2026-21367 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | ||
| CVE-2025-59614 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. | ||
| CVE-2025-59613 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing multiple IOCTL command for escape operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL calls for escape operations.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when handling power management requests with improperly sized input/output buffers.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when retrieving output buffer with insufficient size validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while preprocessing IOCTL request in JPEG driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when sending random number generator command with insufficient output buffer size.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
Page 1 of 2