Snapdragon Auto 4g Modem Firmware
by Qualcomm
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33038 | Med | 0.44 | 6.7 | 0.00 | Jan 2, 2024 | Memory corruption while receiving a message in Bus Socket Transport Server. | ||
| CVE-2022-33227 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2025-47333 | Med | 0.43 | 6.6 | 0.00 | Jan 7, 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | ||
| CVE-2023-28572 | Med | 0.43 | 6.6 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN HOST while processing the WLAN scan descriptor list. | ||
| CVE-2023-28539 | Med | 0.43 | 6.6 | 0.00 | Oct 3, 2023 | Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47404 | Med | 0.42 | 6.5 | 0.00 | May 4, 2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | ||
| CVE-2025-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2024-21459 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon or probe response frame in STA. | ||
| CVE-2024-33067 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | ||
| CVE-2023-43528 | Med | 0.40 | 6.1 | 0.00 | May 6, 2024 | Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | ||
| CVE-2023-28569 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28566 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling the WMI state info command. | ||
| CVE-2023-28563 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. | ||
| CVE-2023-28553 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. | ||
| CVE-2023-28571 | Med | 0.40 | 6.1 | 0.00 | Oct 3, 2023 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption while receiving a message in Bus Socket Transport Server.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while handling buffer mapping operations in the cryptographic driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon or probe response frame in STA.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
- risk 0.40cvss 6.1epss 0.00
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling command through WMI interfaces.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling the WMI state info command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in IOE Firmware while handling WMI command.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in WLAN Host when processing WMI event command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Page 6 of 7