Qca0000 Firmware
by Qualcomm
CVEs (456)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49830 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while processing an IOCTL call to set mixer controls. | ||
| CVE-2024-45581 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while sound model registration for voice activation with audio kernel driver. | ||
| CVE-2024-45562 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. | ||
| CVE-2024-45544 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while processing IOCTL calls to add route entry in the HW. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-47371 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | ||
| CVE-2025-47402 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. | ||
| CVE-2025-47325 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. | ||
| CVE-2025-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | ||
| CVE-2025-27040 | Med | 0.42 | 6.5 | 0.00 | Oct 9, 2025 | Information disclosure may occur while processing the hypervisor log. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2024-45556 | Med | 0.42 | 6.5 | 0.00 | Apr 7, 2025 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | ||
| CVE-2024-21467 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon probe frame during scan entry generation in client side. |
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing an IOCTL call to set mixer controls.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while sound model registration for voice activation with audio kernel driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption during concurrent access to server info object due to unprotected critical field.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL calls to add route entry in the HW.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a received frame with an excessively large authentication information element.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing system calls with invalid parameters.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- risk 0.42cvss 6.5epss 0.00
Information disclosure may occur while processing the hypervisor log.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.42cvss 6.5epss 0.00
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon probe frame during scan entry generation in client side.
Page 21 of 23