Wcn3660b Firmware
by Qualcomm
CVEs (548)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27037 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers. | ||
| CVE-2025-27062 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | ||
| CVE-2025-21474 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing commands from A2dp sink command queue. | ||
| CVE-2025-21456 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently. | ||
| CVE-2025-27061 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | ||
| CVE-2025-27052 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing data packets in diag received from Unix clients. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21486 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. | ||
| CVE-2025-21467 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-45579 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check. | ||
| CVE-2024-45578 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while acquire and update IOCTLs during IFE output resource ID validation. | ||
| CVE-2024-45577 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. | ||
| CVE-2024-45576 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while prociesing command buffer buffer in OPE module. | ||
| CVE-2024-45575 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption Camera kernel when large number of devices are attached through userspace. | ||
| CVE-2024-45574 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during array access in Camera kernel due to invalid index from invalid command data. | ||
| CVE-2024-45567 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while encoding JPEG format. | ||
| CVE-2024-45566 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent buffer access due to modification of the reference count. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling client exceptions, allowing unauthorized channel access.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing commands from A2dp sink command queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
- risk 0.51cvss 7.8epss 0.00
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing data packets in diag received from Unix clients.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading the FW response from the shared queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while prociesing command buffer buffer in OPE module.
- risk 0.51cvss 7.8epss 0.00
Memory corruption Camera kernel when large number of devices are attached through userspace.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during array access in Camera kernel due to invalid index from invalid command data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while encoding JPEG format.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent buffer access due to modification of the reference count.
Page 10 of 28