Qcn9003 Firmware
by Qualcomm
CVEs (74)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2023-43513 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | ||
| CVE-2023-28573 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing WMI command parameters. | ||
| CVE-2023-28567 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28557 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28549 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | ||
| CVE-2023-28548 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | ||
| CVE-2023-28541 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | ||
| CVE-2023-24854 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. | ||
| CVE-2023-24851 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while parsing QMI response message from firmware. | ||
| CVE-2023-22386 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. | ||
| CVE-2025-47318 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. | ||
| CVE-2025-27073 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while creating NDP instance. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2023-33105 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43523 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while processing 11AZ RTT management action frame received through OTA. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing WMI command parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the EPTM test control message to get the test pattern.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while creating NDP instance.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing 11AZ RTT management action frame received through OTA.
Page 2 of 4