Qcm6490 Firmware
by Qualcomm
CVEs (776)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1918 | Med | 0.42 | 6.5 | 0.00 | Jan 3, 2022 | Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-1960 | Med | 0.42 | 6.5 | 0.00 | Sep 9, 2021 | Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2021-1957 | Med | 0.42 | 6.5 | 0.00 | Sep 9, 2021 | Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2025-47406 | Med | 0.40 | 6.1 | 0.00 | May 4, 2026 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-27036 | Med | 0.40 | 6.1 | 0.00 | Sep 24, 2025 | Information disclosure when Video engine escape input data is less than expected minimum size. | ||
| CVE-2025-27033 | Med | 0.40 | 6.1 | 0.00 | Sep 24, 2025 | Information disclosure while running video usecase having rogue firmware. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2024-23357 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | ||
| CVE-2023-28569 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28566 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling the WMI state info command. | ||
| CVE-2023-28563 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. | ||
| CVE-2022-40533 | Med | 0.40 | 6.2 | 0.00 | Jun 6, 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | ||
| CVE-2022-22075 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2023 | Information Disclosure in Graphics during GPU context switch. | ||
| CVE-2022-25725 | Med | 0.40 | 6.2 | 0.00 | Jan 9, 2023 | Denial of service in MODEM due to improper pointer handling | ||
| CVE-2022-25679 | Med | 0.40 | 6.2 | 0.00 | Nov 15, 2022 | Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-25664 | Med | 0.40 | 6.2 | 0.00 | Oct 19, 2022 | Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-35135 | Med | 0.40 | 6.2 | 0.00 | Sep 2, 2022 | A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-30314 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2022 | Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
- risk 0.42cvss 6.5epss 0.00
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.42cvss 6.5epss 0.00
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.42cvss 6.5epss 0.00
Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.40cvss 6.1epss 0.00
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.40cvss 6.1epss 0.00
Information disclosure when Video engine escape input data is less than expected minimum size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while running video usecase having rogue firmware.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.40cvss 6.2epss 0.00
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling command through WMI interfaces.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling the WMI state info command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in IOE Firmware while handling WMI command.
- risk 0.40cvss 6.2epss 0.00
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
- risk 0.40cvss 6.2epss 0.00
Information Disclosure in Graphics during GPU context switch.
- risk 0.40cvss 6.2epss 0.00
Denial of service in MODEM due to improper pointer handling
- risk 0.40cvss 6.2epss 0.00
Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Page 37 of 39