U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:qualcomm:snapdragon_auto_5g_modem-rf_firmware:-:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 165 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2025-21468

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

Published: May 06, 2025; 5:15:24 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21467

Memory corruption while reading the FW response from the shared queue.

Published: May 06, 2025; 5:15:23 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21453

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

Published: May 06, 2025; 5:15:22 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2025-21424

Memory corruption while calling the NPU driver APIs concurrently.

Published: March 03, 2025; 6:15:15 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-53027

Transient DOS may occur while processing the country IE.

Published: March 03, 2025; 6:15:14 AM -0500
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2024-43051

Information disclosure while deriving keys for a session for any Widevine use case.

Published: March 03, 2025; 6:15:11 AM -0500
V4.0:(not available)
V3.1: 5.5 MEDIUM
V2.0:(not available)
CVE-2024-33056

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

Published: December 02, 2024; 6:15:08 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-33044

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

Published: December 02, 2024; 6:15:08 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38423

Memory corruption while processing GPU page table switch.

Published: November 04, 2024; 5:15:09 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38422

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Published: November 04, 2024; 5:15:08 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38419

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Published: November 04, 2024; 5:15:08 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38415

Memory corruption while handling session errors from firmware.

Published: November 04, 2024; 5:15:08 AM -0500
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38408

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Published: November 04, 2024; 5:15:07 AM -0500
V4.0:(not available)
V3.1: 9.1 CRITICAL
V2.0:(not available)
CVE-2024-43047

Memory corruption while maintaining memory maps of HLOS memory.

Published: October 07, 2024; 9:15:15 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-33049

Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

Published: October 07, 2024; 9:15:12 AM -0400
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2024-38402

Memory corruption while processing IOCTL call for getting group info.

Published: September 02, 2024; 8:15:19 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-38401

Memory corruption while processing concurrent IOCTL calls.

Published: September 02, 2024; 8:15:18 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-33060

Memory corruption when two threads try to map and unmap a single node simultaneously.

Published: September 02, 2024; 8:15:18 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2024-33050

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Published: September 02, 2024; 8:15:17 AM -0400
V4.0:(not available)
V3.1: 7.5 HIGH
V2.0:(not available)
CVE-2024-33045

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Published: September 02, 2024; 8:15:16 AM -0400
V4.0:(not available)
V3.1: 7.8 HIGH
V2.0:(not available)