Snapdragon 6 Gen 3 Mobile Platform Firmware
by Qualcomm
CVEs (129)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59600 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | ||
| CVE-2025-47385 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | ||
| CVE-2025-47373 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | ||
| CVE-2025-47398 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | ||
| CVE-2025-47397 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | ||
| CVE-2025-47320 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while processing MFC channel configuration during music playback. | ||
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2025-27061 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21467 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-49835 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading secure file. | ||
| CVE-2024-45566 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent buffer access due to modification of the reference count. | ||
| CVE-2024-45564 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to incorrect reference count update. | ||
| CVE-2024-38418 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while parsing the memory map info in IOCTL calls. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when adding user-supplied data without checking available buffer space.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing trusted execution environment without proper privilege check.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing buffers with invalid length during TA invocation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing MFC channel configuration during music playback.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading the FW response from the shared queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading secure file.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent buffer access due to modification of the reference count.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent access to server info object due to incorrect reference count update.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while parsing the memory map info in IOCTL calls.
Page 3 of 7