Search Results (655 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-45549 1 Qualcomm 320 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 317 more 2025-10-06 7.7 High
Information disclosure while creating MQ channels.
CVE-2025-21448 1 Qualcomm 538 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 535 more 2025-10-06 7.5 High
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21430 1 Qualcomm 450 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 447 more 2025-10-06 7.5 High
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2024-33058 1 Qualcomm 379 Aqt1000, Aqt1000 Firmware, Ar8035 and 376 more 2025-10-03 7.5 High
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
CVE-2024-33016 1 Qualcomm 669 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 666 more 2025-10-03 6.8 Medium
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23364 1 Qualcomm 359 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 356 more 2025-10-03 7.5 High
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-23362 1 Qualcomm 466 9205 Lte Modem, 9205 Lte Modem Firmware, Aqt1000 and 463 more 2025-10-03 7.1 High
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359 1 Qualcomm 324 205 Mobile Platform, 205 Mobile Platform Firmware, 315 5g Iot Modem and 321 more 2025-10-03 8.2 High
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2025-27042 1 Qualcomm 689 215 Mobile, 215 Mobile Firmware, 315 5g Iot Modem and 686 more 2025-09-25 7.8 High
Memory corruption while processing video packets received from video firmware.
CVE-2025-21452 1 Qualcomm 161 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 158 more 2025-08-20 7.5 High
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2023-33085 1 Qualcomm 210 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 207 more 2025-08-11 7.8 High
Memory corruption in wearables while processing data from AON.
CVE-2023-33113 1 Qualcomm 254 Ar8035, Ar8035 Firmware, Csra6620 and 251 more 2025-08-11 8.4 High
Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.
CVE-2023-33112 1 Qualcomm 255 Ar8035, Ar8035 Firmware, Csra6620 and 252 more 2025-08-11 7.5 High
Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.
CVE-2023-43513 1 Qualcomm 534 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 531 more 2025-08-11 7.8 High
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
CVE-2023-28550 1 Qualcomm 670 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 667 more 2025-08-11 7.8 High
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-33104 1 Qualcomm 204 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 201 more 2025-08-11 7.5 High
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
CVE-2023-33120 1 Qualcomm 464 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9206 Lte Modem and 461 more 2025-08-11 7.8 High
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
CVE-2023-24854 1 Qualcomm 326 215, 215 Firmware, Ar8035 and 323 more 2025-08-11 7.8 High
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
CVE-2023-43536 1 Qualcomm 618 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 615 more 2025-08-11 7.5 High
Transient DOS while parse fils IE with length equal to 1.
CVE-2024-23369 1 Qualcomm 237 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 234 more 2025-08-11 7.8 High
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.