Export limit exceeded: 403784 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (532 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57554 | 1 Qualcomm | 437 Ar8031, Ar8031 Firmware, Ar8035 and 434 more | 2026-10-09 | 7.8 High |
| Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations. | ||||
| CVE-2026-57545 | 1 Qualcomm | 435 Ar8031, Ar8031 Firmware, Cologne and 432 more | 2026-10-09 | 7.8 High |
| Memory corruption when processing draw objects of incorrect type during graphics command list execution. | ||||
| CVE-2026-57537 | 1 Qualcomm | 145 Congo, Congo Firmware, Fastconnect 6200 and 142 more | 2026-10-09 | 7.8 High |
| Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization. | ||||
| CVE-2026-25302 | 1 Qualcomm | 584 Ar8035, Ar8035 Firmware, Cologne and 581 more | 2026-10-09 | 7.1 High |
| Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed. | ||||
| CVE-2026-25291 | 1 Qualcomm | 227 Cq8845s, Cq8845s Firmware, Cq8850ns and 224 more | 2026-10-09 | 7.8 High |
| Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms. | ||||
| CVE-2026-25272 | 1 Qualcomm | 311 Cologne, Cologne Firmware, Cq2390m and 308 more | 2026-10-09 | 6.7 Medium |
| Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. | ||||
| CVE-2026-25270 | 1 Qualcomm | 407 Cologne, Cologne Firmware, Congo and 404 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | ||||
| CVE-2026-25269 | 1 Qualcomm | 313 Cologne, Cologne Firmware, Cq2390m and 310 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | ||||
| CVE-2026-25267 | 1 Qualcomm | 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more | 2026-10-09 | 7.8 High |
| Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | ||||
| CVE-2026-25263 | 1 Qualcomm | 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more | 2026-10-09 | 6.6 Medium |
| Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | ||||
| CVE-2026-25275 | 1 Qualcomm | 753 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Aqt1000 and 750 more | 2026-09-22 | 7.5 High |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. | ||||
| CVE-2026-24081 | 1 Qualcomm | 305 Ar8035, Ar8035 Firmware, C110100 and 302 more | 2026-09-22 | 7.4 High |
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | ||||
| CVE-2026-25278 | 1 Qualcomm | 59 Lemans Au Lgit, Lemans Au Lgit Firmware, Lemansau and 56 more | 2026-09-22 | 7.8 High |
| Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | ||||
| CVE-2026-24079 | 1 Qualcomm | 287 Ar8035, Ar8035 Firmware, Csra6620 and 284 more | 2026-08-07 | 8.1 High |
| Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | ||||
| CVE-2026-25292 | 1 Qualcomm | 423 Ar8031, Ar8031 Firmware, Ar8035 and 420 more | 2026-08-05 | 7.6 High |
| Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | ||||
| CVE-2026-25289 | 1 Qualcomm | 403 Ar8035, Ar8035 Firmware, Cologne and 400 more | 2026-08-05 | 9.6 Critical |
| Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | ||||
| CVE-2026-24078 | 1 Qualcomm | 295 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Ar8035 and 292 more | 2026-08-04 | 6.5 Medium |
| Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||||
| CVE-2026-24084 | 1 Qualcomm | 257 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Aqt1000 and 254 more | 2026-08-04 | 7.5 High |
| Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | ||||
| CVE-2026-21366 | 1 Qualcomm | 67 Lemans Au Lgit, Lemans Au Lgit Firmware, Lemansau and 64 more | 2026-08-04 | 7.8 High |
| Memory corruption while processing a packet with a size close to the maximum allowed value. | ||||
| CVE-2025-38293 | 3 Debian, Linux, Qualcomm | 3 Debian Linux, Linux Kernel, Qca6698aq | 2026-07-30 | 8.8 High |
| In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath11k_core_halt() only reinitializes the "arvifs" list head. This will cause the list node immediately following the list head to become an invalid list node. Because the prev of that node still points to the list head "arvifs", but the next of the list head "arvifs" no longer points to that list node. When a WLAN recovery occurs during the execution of a vif removal, and it happens before the spin_lock_bh(&ar->data_lock) in ath11k_mac_op_remove_interface(), list_del() will detect the previously mentioned situation, thereby triggering a kernel panic. The fix is to remove and reinitialize all vif list nodes from the list head "arvifs" during WLAN halt. The reinitialization is to make the list nodes valid, ensuring that the list_del() in ath11k_mac_op_remove_interface() can execute normally. Call trace: __list_del_entry_valid_or_report+0xb8/0xd0 ath11k_mac_op_remove_interface+0xb0/0x27c [ath11k] drv_remove_interface+0x48/0x194 [mac80211] ieee80211_do_stop+0x6e0/0x844 [mac80211] ieee80211_stop+0x44/0x17c [mac80211] __dev_close_many+0xac/0x150 __dev_change_flags+0x194/0x234 dev_change_flags+0x24/0x6c devinet_ioctl+0x3a0/0x670 inet_ioctl+0x200/0x248 sock_do_ioctl+0x60/0x118 sock_ioctl+0x274/0x35c __arm64_sys_ioctl+0xac/0xf0 invoke_syscall+0x48/0x114 ... Tested-on: QCA6698AQ hw2.1 PCI WLAN.HSP.1.1-04591-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 | ||||