Qmp1000 Firmware
by Qualcomm
CVEs (117)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27056 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during sub-system restart while processing clean-up to free up resources. | ||
| CVE-2025-27052 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing data packets in diag received from Unix clients. | ||
| CVE-2025-27043 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing manipulated payload in video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21486 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. | ||
| CVE-2025-21485 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-49835 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading secure file. | ||
| CVE-2025-21436 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads. | ||
| CVE-2024-53024 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption in display driver while detaching a device. | ||
| CVE-2024-53014 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while validating ports and channels in Audio driver. | ||
| CVE-2024-53011 | Hig | 0.51 | 7.9 | 0.00 | Mar 3, 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. | ||
| CVE-2024-49836 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during the synchronization of the camera`s frame processing pipeline. | ||
| CVE-2024-45580 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption during sub-system restart while processing clean-up to free up resources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing data packets in diag received from Unix clients.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing manipulated payload in video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading secure file.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in display driver while detaching a device.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while validating ports and channels in Audio driver.
- risk 0.51cvss 7.9epss 0.00
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
Page 3 of 6