Sa8295p Firmware
by Qualcomm
CVEs (478)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47364 | Med | 0.44 | 6.8 | 0.00 | Feb 2, 2026 | Memory corruption while calculating offset from partition start point. | ||
| CVE-2025-47363 | Med | 0.44 | 6.8 | 0.00 | Feb 2, 2026 | Memory corruption when calculating oversized partition sizes without proper checks. | ||
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2024-49848 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | Memory corruption while processing multiple IOCTL calls from HLOS to DSP. | ||
| CVE-2024-33055 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption while invoking IOCTL calls to unmap the DMA buffers. | ||
| CVE-2024-33041 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | ||
| CVE-2024-33053 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when multiple threads try to unregister the CVP buffer at the same time. | ||
| CVE-2024-33036 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | ||
| CVE-2024-33032 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2023-43527 | Med | 0.44 | 6.8 | 0.00 | May 6, 2024 | Information disclosure while parsing dts header atom in Video. | ||
| CVE-2023-43526 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption while querying module parameters from Listen Sound model client in kernel from user space. | ||
| CVE-2023-43525 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption while copying the sound model data from user to kernel buffer during sound model register. | ||
| CVE-2023-43524 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when the bandpass filter order received from AHAL is not within the expected range. | ||
| CVE-2023-43521 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when multiple listeners are being registered with the same file descriptor. | ||
| CVE-2023-33077 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. | ||
| CVE-2023-33069 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. | ||
| CVE-2023-33068 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. | ||
| CVE-2023-33067 | Med | 0.44 | 6.7 | 0.00 | Feb 6, 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. | ||
| CVE-2023-33024 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory corruption while sending SMS from AP firmware. |
- risk 0.44cvss 6.8epss 0.00
Memory corruption while calculating offset from partition start point.
- risk 0.44cvss 6.8epss 0.00
Memory corruption when calculating oversized partition sizes without proper checks.
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.44cvss 6.8epss 0.00
Information disclosure while parsing dts header atom in Video.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple listeners are being registered with the same file descriptor.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in HLOS while converting from authorization token to HIDL vector.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while processing IIR config data from AFE calibration block.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending SMS from AP firmware.
Page 20 of 24