Qrb5165m Firmware
by Qualcomm
CVEs (260)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2026-24077 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2024-23357 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | ||
| CVE-2022-40533 | Med | 0.40 | 6.2 | 0.00 | Jun 6, 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | ||
| CVE-2021-35135 | Med | 0.40 | 6.2 | 0.00 | Sep 2, 2022 | A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2025-47369 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2021-35084 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2021-35071 | Med | 0.36 | 5.5 | 0.00 | Jun 14, 2022 | Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,… |
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.40cvss 6.2epss 0.00
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
- risk 0.40cvss 6.2epss 0.00
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
- risk 0.40cvss 6.2epss 0.00
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.36cvss 5.5epss 0.00
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.36cvss 5.5epss 0.00
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,…
Page 13 of 13