Snapdragon X75 5g Modem Rf Firmware
by Qualcomm
CVEs (83)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21463 | Hig | 0.47 | 7.3 | 0.00 | Apr 1, 2024 | Memory corruption while processing Codec2 during v13k decoder pitch synthesis. | ||
| CVE-2025-47366 | Hig | 0.46 | 7.1 | 0.00 | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2023-43545 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption when more scan frequency list or channels are sent from the user space. | ||
| CVE-2023-43544 | Med | 0.44 | 6.7 | 0.00 | Jun 3, 2024 | Memory corruption when IPC callback handle is used after it has been released during register callback by another thread. | ||
| CVE-2023-43526 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption while querying module parameters from Listen Sound model client in kernel from user space. | ||
| CVE-2023-43525 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption while copying the sound model data from user to kernel buffer during sound model register. | ||
| CVE-2023-43524 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when the bandpass filter order received from AHAL is not within the expected range. | ||
| CVE-2023-43521 | Med | 0.44 | 6.7 | 0.00 | May 6, 2024 | Memory corruption when multiple listeners are being registered with the same file descriptor. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47403 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | ||
| CVE-2025-47401 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Transient DOS when processing target power rate tables during channel configuration. | ||
| CVE-2025-47402 | Med | 0.42 | 6.5 | 0.00 | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. | ||
| CVE-2023-43537 | Med | 0.42 | 6.5 | 0.00 | Jun 3, 2024 | Information disclosure while handling T2LM Action Frame in WLAN Host. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-38417 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure while processing IO control commands. | ||
| CVE-2024-38416 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure during audio playback. | ||
| CVE-2024-33067 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | ||
| CVE-2023-43528 | Med | 0.40 | 6.1 | 0.00 | May 6, 2024 | Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | ||
| CVE-2023-43530 | Med | 0.38 | 5.9 | 0.00 | May 6, 2024 | Memory corruption in HLOS while checking for the storage type. |
- risk 0.47cvss 7.3epss 0.00
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when more scan frequency list or channels are sent from the user space.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple listeners are being registered with the same file descriptor.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing target power rate tables during channel configuration.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when processing a received frame with an excessively large authentication information element.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling T2LM Action Frame in WLAN Host.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing IO control commands.
- risk 0.40cvss 6.1epss 0.00
Information disclosure during audio playback.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
- risk 0.40cvss 6.1epss 0.00
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
- risk 0.38cvss 5.9epss 0.00
Memory corruption in HLOS while checking for the storage type.
Page 4 of 5