Mdm9628 Firmware
by Qualcomm
CVEs (266)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21649 | Med | 0.44 | 6.7 | 0.00 | Aug 8, 2023 | Memory corruption in WLAN while running doDriverCmd for an unspecific command. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2022-33225 | Med | 0.44 | 6.7 | 0.00 | Feb 12, 2023 | Memory corruption due to use after free in trusted application environment. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2024-53013 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing voice call registration with user. | ||
| CVE-2024-45581 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while sound model registration for voice activation with audio kernel driver. | ||
| CVE-2023-28572 | Med | 0.43 | 6.6 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN HOST while processing the WLAN scan descriptor list. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2021-30348 | Med | 0.42 | 6.5 | 0.00 | Jan 3, 2022 | Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-27064 | Med | 0.40 | 6.1 | 0.00 | Nov 4, 2025 | Information disclosure while registering commands from clients with diag through diagHal. | ||
| CVE-2022-22075 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2023 | Information Disclosure in Graphics during GPU context switch. | ||
| CVE-2021-1904 | Med | 0.40 | 6.2 | 0.01 | Sep 8, 2021 | Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2022-33296 | Med | 0.38 | 5.9 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | ||
| CVE-2022-33266 | Med | 0.38 | 5.9 | 0.00 | Jan 9, 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. | ||
| CVE-2025-47369 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in trusted application environment.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing voice call registration with user.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while sound model registration for voice activation with audio kernel driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while registering commands from clients with diag through diagHal.
- risk 0.40cvss 6.2epss 0.00
Information Disclosure in Graphics during GPU context switch.
- risk 0.40cvss 6.2epss 0.01
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.38cvss 5.9epss 0.00
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
- risk 0.38cvss 5.9epss 0.00
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
Page 13 of 14