Qca6420 Firmware
by Qualcomm
CVEs (585)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21373 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | ||
| CVE-2026-21371 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | ||
| CVE-2025-47359 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when multiple threads simultaneously access a memory free API. | ||
| CVE-2025-47387 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory Corruption when processing IOCTLs for JPEG data without verification. | ||
| CVE-2025-27054 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing a malformed license file during reboot. | ||
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2025-47327 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while encoding the image data. | ||
| CVE-2025-47316 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption due to double free when multiple threads race to set the timestamp store. | ||
| CVE-2025-27032 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency. | ||
| CVE-2025-21481 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. | ||
| CVE-2025-27076 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing simultaneous requests via escape path. | ||
| CVE-2025-27075 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host. | ||
| CVE-2025-27061 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | ||
| CVE-2025-27055 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during the image encoding process. | ||
| CVE-2025-27050 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing event close when client process terminates abruptly. | ||
| CVE-2025-27046 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing multiple simultaneous escape calls. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21466 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing a private escape command in an event trigger. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2024-53010 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when retrieving output buffer with insufficient size validation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when multiple threads simultaneously access a memory free API.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when processing IOCTLs for JPEG data without verification.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a malformed license file during reboot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while encoding the image data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to double free when multiple threads race to set the timestamp store.
- risk 0.51cvss 7.8epss 0.00
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while performing private key encryption in trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing simultaneous requests via escape path.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
- risk 0.51cvss 7.8epss 0.00
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the image encoding process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing event close when client process terminates abruptly.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing multiple simultaneous escape calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a private escape command in an event trigger.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
Page 11 of 30