Qcn9024 Firmware
by Qualcomm
CVEs (455)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2022-25722 | Med | 0.39 | 6.0 | 0.00 | Jan 9, 2023 | Information exposure in DSP services due to improper handling of freeing memory | ||
| CVE-2020-3664 | Med | 0.39 | 6.0 | 0.00 | Feb 22, 2021 | Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2023-33076 | Med | 0.38 | 5.9 | 0.00 | Feb 6, 2024 | Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | ||
| CVE-2022-33296 | Med | 0.38 | 5.9 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | ||
| CVE-2025-59609 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | ||
| CVE-2025-47369 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2024-43046 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2021-35071 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,… | ||
| CVE-2024-38426 | Med | 0.35 | 5.4 | 0.00 | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | ||
| CVE-2021-1903 | Med | 0.34 | 5.3 | 0.01 | Nov 12, 2021 | Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… | ||
| CVE-2021-1928 | Med | 0.30 | 4.6 | 0.00 | Sep 8, 2021 | Buffer over read could occur due to incorrect check of buffer size while flashing emmc devices in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and… | ||
| CVE-2026-25268 | Hig | 0.00 | 8.8 | 0.00 | Jul 6, 2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. |
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.39cvss 6.0epss 0.00
Information exposure in DSP services due to improper handling of freeing memory
- risk 0.39cvss 6.0epss 0.00
Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.38cvss 5.9epss 0.00
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
- risk 0.38cvss 5.9epss 0.00
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
- risk 0.36cvss 5.5epss 0.00
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
There may be information disclosure during memory re-allocation in TZ Secure OS.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.36cvss 5.5epss 0.00
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,…
- risk 0.35cvss 5.4epss 0.00
While processing the authentication message in UE, improper authentication may lead to information disclosure.
- risk 0.34cvss 5.3epss 0.01
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
- risk 0.30cvss 4.6epss 0.00
Buffer over read could occur due to incorrect check of buffer size while flashing emmc devices in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and…
- risk 0.00cvss 8.8epss 0.00
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Page 23 of 23