Sm8650q Firmware
by Qualcomm
CVEs (117)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-47371 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | ||
| CVE-2025-47402 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. | ||
| CVE-2025-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-27033 | Med | 0.40 | 6.1 | 0.00 | Sep 24, 2025 | Information disclosure while running video usecase having rogue firmware. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2025-59609 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | ||
| CVE-2025-47369 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2024-43046 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. | ||
| CVE-2024-43056 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2024-38426 | Med | 0.35 | 5.4 | 0.00 | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. |
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a received frame with an excessively large authentication information element.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while running video usecase having rogue firmware.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.36cvss 5.5epss 0.00
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
There may be information disclosure during memory re-allocation in TZ Secure OS.
- risk 0.36cvss 5.5epss 0.00
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.35cvss 5.4epss 0.00
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Page 6 of 6