U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 506 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2025-21468

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

Published: May 06, 2025; 5:15:24 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21467

Memory corruption while reading the FW response from the shared queue.

Published: May 06, 2025; 5:15:23 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21453

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

Published: May 06, 2025; 5:15:22 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-49842

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

Published: May 06, 2025; 5:15:21 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-49841

Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.

Published: May 06, 2025; 5:15:21 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-49830

Memory corruption while processing an IOCTL call to set mixer controls.

Published: May 06, 2025; 5:15:21 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-45581

Memory corruption while sound model registration for voice activation with audio kernel driver.

Published: May 06, 2025; 5:15:20 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-45564

Memory corruption during concurrent access to server info object due to incorrect reference count update.

Published: May 06, 2025; 5:15:18 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-45562

Memory corruption during concurrent access to server info object due to unprotected critical field.

Published: May 06, 2025; 5:15:18 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21424

Memory corruption while calling the NPU driver APIs concurrently.

Published: March 03, 2025; 6:15:15 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-53027

Transient DOS may occur while processing the country IE.

Published: March 03, 2025; 6:15:14 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2024-53014

Memory corruption may occur while validating ports and channels in Audio driver.

Published: March 03, 2025; 6:15:13 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-43061

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

Published: March 03, 2025; 6:15:12 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-43060

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

Published: March 03, 2025; 6:15:12 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-43057

Memory corruption while processing command in Glink linux.

Published: March 03, 2025; 6:15:11 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-43056

Transient DOS during hypervisor virtual I/O operation in a virtual machine.

Published: March 03, 2025; 6:15:11 AM -0500
V4.0:(not available)
V3.1: 6.5 MEDIUM
V2.0:(not available)
CVE-2024-38426

While processing the authentication message in UE, improper authentication may lead to information disclosure.

Published: March 03, 2025; 6:15:11 AM -0500
V4.0:(not available)
V3.1: 5.3 MEDIUM
V2.0:(not available)
CVE-2024-49838

Information disclosure while parsing the OCI IE with invalid length.

Published: February 03, 2025; 12:15:20 PM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2024-38420

Memory corruption while configuring a Hypervisor based input virtual device.

Published: February 03, 2025; 12:15:18 PM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38417

Information disclosure while processing IO control commands.

Published: February 03, 2025; 12:15:17 PM -0500
V4.0:(not available)
V3.1: 5.5 MEDIUM
V2.0:(not available)