Ipq5300 Firmware
by Qualcomm
CVEs (55)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45569 | Cri | 0.64 | 9.8 | 0.00 | Feb 3, 2025 | Memory corruption while parsing the ML IE due to invalid frame content. | ||
| CVE-2024-33066 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2024 | Memory corruption while redirecting log file to any file location with any file name. | ||
| CVE-2024-21473 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2024 | Memory corruption while redirecting log file to any file location with any file name. | ||
| CVE-2026-25289 | Cri | 0.62 | 9.6 | 0.00 | Aug 4, 2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-49839 | Hig | 0.53 | 8.2 | 0.00 | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. | ||
| CVE-2024-33073 | Hig | 0.53 | 8.2 | 0.00 | Oct 7, 2024 | Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | ||
| CVE-2024-43057 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing command in Glink linux. | ||
| CVE-2024-45571 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2025-47328 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while processing power control requests with invalid antenna or stream values. | ||
| CVE-2025-47326 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while handling command data during power control processing. | ||
| CVE-2025-27065 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a frame with malformed shared-key descriptor. | ||
| CVE-2025-27057 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. | ||
| CVE-2025-27029 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | ||
| CVE-2025-21463 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. | ||
| CVE-2025-21435 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. | ||
| CVE-2024-45558 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | ||
| CVE-2024-33063 | Hig | 0.49 | 7.5 | 0.00 | Dec 2, 2024 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. | ||
| CVE-2024-38397 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing probe response and assoc response frame. |
- risk 0.64cvss 9.8epss 0.00
Memory corruption while parsing the ML IE due to invalid frame content.
- risk 0.64cvss 9.8epss 0.01
Memory corruption while redirecting log file to any file location with any file name.
- risk 0.64cvss 9.8epss 0.01
Memory corruption while redirecting log file to any file location with any file name.
- risk 0.62cvss 9.6epss 0.00
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.53cvss 8.2epss 0.00
Memory corruption during management frame processing due to mismatch in T2LM info element.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing command in Glink linux.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing power control requests with invalid antenna or stream values.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling command data during power control processing.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a frame with malformed shared-key descriptor.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling beacon frames with invalid IE header length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the EHT operation IE in the received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing extended IE in beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing probe response and assoc response frame.
Page 1 of 3