C V2x 9150 Firmware
by Qualcomm
CVEs (118)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2025-27030 | Med | 0.40 | 6.1 | 0.00 | Sep 24, 2025 | information disclosure while invoking calibration data from user space to update firmware size. | ||
| CVE-2024-38417 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure while processing IO control commands. | ||
| CVE-2024-38416 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure during audio playback. | ||
| CVE-2024-33067 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | ||
| CVE-2024-33037 | Med | 0.40 | 6.1 | 0.00 | Dec 2, 2024 | Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. | ||
| CVE-2023-43528 | Med | 0.40 | 6.1 | 0.00 | May 6, 2024 | Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | ||
| CVE-2023-33065 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | Information disclosure in Audio while accessing AVCS services from ADSP payload. | ||
| CVE-2023-28554 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2024-43051 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. | ||
| CVE-2023-33111 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2024 | Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. |
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.40cvss 6.1epss 0.00
information disclosure while invoking calibration data from user space to update firmware size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing IO control commands.
- risk 0.40cvss 6.1epss 0.00
Information disclosure during audio playback.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
- risk 0.40cvss 6.1epss 0.00
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
- risk 0.40cvss 6.1epss 0.00
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in Audio while accessing AVCS services from ADSP payload.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Information disclosure while deriving keys for a session for any Widevine use case.
- risk 0.36cvss 5.5epss 0.00
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
Page 6 of 6