VendorsQualcommqcn9074_firmwareall versions
Vulnerabilities

Qualcomm QCN9074 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

343CVEs
CVE-2023-33068
Buffer Copy Without Checking Size of Input in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-33069
Buffer Copy Without Checking Size of Input in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-43521
Use After Free in HLOS
Published 2024-05-06 · Analyzed
7.8EPSS 0.001
CVE-2023-33067
Use of Out-of-range Pointer Offset in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-33077
Buffer Copy Without Checking Size of Input in HLOS
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2024-45570
Use of Out-of-range Pointer Offset in Camera Driver
Published 2025-05-06 · Analyzed
7.8EPSS 0.001
CVE-2024-45562
Use After Free in HLOS
Published 2025-05-06 · Analyzed
7.8EPSS 0.001
CVE-2024-38422
Integer Overflow to Buffer Overflow in Audio
Published 2024-11-04 · Analyzed
7.8EPSS 0.001
CVE-2024-38423
Buffer Copy Without Checking Size of Input in Graphics Linux
Published 2024-11-04 · Analyzed
7.8EPSS 0.001
CVE-2024-45571
Use After Free in WLAN Host Communication
Published 2025-02-03 · Analyzed
7.8EPSS 0.001
CVE-2024-23368
Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Qualcomm IPC
Published 2024-07-01 · Modified
7.8EPSS 0.001
CVE-2022-40529
Improper access control in Kernel
Published 2023-06-06 · Modified
7.8EPSS 0.001
CVE-2024-43067
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera
Published 2025-04-07 · Analyzed
7.8EPSS 0.001
CVE-2025-27043
Buffer Copy Without Checking Size of Input in Video
Published 2025-07-08 · Analyzed
7.8EPSS 0.001
CVE-2025-21474
Use After Free in BTHOST
Published 2025-08-06 · Analyzed
7.8EPSS 0.001
CVE-2025-27053
Incorrect Calculation of Buffer Size in HLOS
Published 2025-10-09 · Analyzed
7.8EPSS 0.001
CVE-2025-27054
Out-of-bounds Write in Display
Published 2025-10-09 · Analyzed
7.8EPSS 0.001
CVE-2025-27037
Use After Free in Camera Driver
Published 2025-09-24 · Analyzed
7.8EPSS 0.001
CVE-2025-47339
Use After Free in HLOS
Published 2026-01-06 · Analyzed
7.8EPSS 0.001
CVE-2024-38418
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Linux
Published 2025-02-03 · Analyzed
7.8EPSS 0.001
CVE-2025-21481
Buffer Copy Without Checking Size of Input in HLOS
Published 2025-09-24 · Analyzed
7.8EPSS 0.001
CVE-2022-25736
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-10-19 · Modified
7.5EPSS 0.008
CVE-2023-33105
Configuration Issue in WLAN Host and Firmware
Published 2024-03-04 · Analyzed
7.5EPSS 0.008
CVE-2020-11281
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-02-22 · Modified
7.5EPSS 0.007
CVE-2021-30302
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-10-20 · Modified
7.5EPSS 0.007
CVE-2021-30312
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-10-20 · Modified
7.5EPSS 0.006
CVE-2021-1937
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-06-09 · Modified
7.5EPSS 0.006
CVE-2021-1938
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1943
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1945
Possible out of bound read due to lack of length check of Bandwidth-NSS IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1953
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1954
Possible buffer over read due to improper validation of data pointer while parsing FILS indication IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1964
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1974
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-09-09 · Modified
7.5EPSS 0.006
CVE-2023-28588
Integer Overflow or Wraparound in Bluetooth Host
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2023-33097
Buffer Over-read in WLAN Firmware
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2023-33098
Buffer Over-read in WLAN Firmware
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2023-33041
Reachable assertion in WLAN Firmware
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2023-33081
Buffer over-read in WLAN Firmware
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2023-33089
NULL Pointer Dereference in WLAN Firmware
Published 2023-12-05 · Modified
7.5EPSS 0.005
← Prev5 / 9Next →