Wcn3660b Firmware
by Qualcomm
CVEs (548)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2024-53018 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing the OIS packet parser. | ||
| CVE-2024-53017 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while handling test pattern generator IOCTL command. | ||
| CVE-2024-53016 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing I2C settings in Camera driver. | ||
| CVE-2024-53015 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. | ||
| CVE-2024-53013 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption may occur while processing voice call registration with user. | ||
| CVE-2024-49830 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while processing an IOCTL call to set mixer controls. | ||
| CVE-2024-45581 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while sound model registration for voice activation with audio kernel driver. | ||
| CVE-2024-45570 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. | ||
| CVE-2024-45563 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session. | ||
| CVE-2024-45562 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. | ||
| CVE-2024-45544 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while processing IOCTL calls to add route entry in the HW. | ||
| CVE-2024-45543 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while accessing MSM channel map and mixer functions. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2024-45556 | Med | 0.42 | 6.5 | 0.00 | Apr 7, 2025 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | ||
| CVE-2023-21667 | Med | 0.42 | 6.5 | 0.00 | Sep 5, 2023 | Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. | ||
| CVE-2023-28576 | Med | 0.42 | 6.4 | 0.00 | Aug 8, 2023 | The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.… | ||
| CVE-2023-21647 | Med | 0.42 | 6.5 | 0.00 | Aug 8, 2023 | Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. |
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing the OIS packet parser.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling test pattern generator IOCTL command.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing I2C settings in Camera driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL command to handle buffers associated with a session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur while processing voice call registration with user.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing an IOCTL call to set mixer controls.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while sound model registration for voice activation with audio kernel driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption during concurrent access to server info object due to unprotected critical field.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL calls to add route entry in the HW.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while accessing MSM channel map and mixer functions.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
- risk 0.42cvss 6.5epss 0.00
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
- risk 0.42cvss 6.4epss 0.00
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.…
- risk 0.42cvss 6.5epss 0.00
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Page 25 of 28