X2000094 Firmware
by Qualcomm
CVEs (54)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47399 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. | ||
| CVE-2025-47359 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when multiple threads simultaneously access a memory free API. | ||
| CVE-2025-47358 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently. | ||
| CVE-2025-47380 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while preprocessing IOCTLs in sensors. | ||
| CVE-2025-47356 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory Corruption when multiple threads concurrently access and modify shared resources. | ||
| CVE-2025-47343 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing a video session to set video parameters. | ||
| CVE-2025-47350 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application. | ||
| CVE-2025-47367 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2025 | Memory corruption while accessing a buffer during IOCTL processing. | ||
| CVE-2025-47352 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2025 | Memory corruption while processing audio streaming operations. | ||
| CVE-2025-47355 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while invoking remote procedure IOCTL calls. | ||
| CVE-2025-47349 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing an escape call. | ||
| CVE-2025-47341 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | memory corruption while processing an image encoding completion event. | ||
| CVE-2025-47340 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing IOCTL call to get the mapping. | ||
| CVE-2025-47338 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing escape commands from userspace. | ||
| CVE-2025-27054 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing a malformed license file during reboot. | ||
| CVE-2025-27048 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing camera platform driver IOCTL calls. | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2026-21367 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | ||
| CVE-2026-25288 | Hig | 0.48 | 7.4 | 0.00 | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||
| CVE-2025-47378 | Hig | 0.46 | 7.1 | 0.00 | Mar 2, 2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when multiple threads simultaneously access a memory free API.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while preprocessing IOCTLs in sensors.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when multiple threads concurrently access and modify shared resources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a video session to set video parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while accessing a buffer during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing audio streaming operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking remote procedure IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing an escape call.
- risk 0.51cvss 7.8epss 0.00
memory corruption while processing an image encoding completion event.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call to get the mapping.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape commands from userspace.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a malformed license file during reboot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing camera platform driver IOCTL calls.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- risk 0.48cvss 7.4epss 0.00
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- risk 0.46cvss 7.1epss 0.00
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Page 2 of 3