VendorsQualcommwcn3990_firmwareall versions
Vulnerabilities

Qualcomm WCN3990 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

415CVEs
CVE-2021-1963
Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-09-09 · Modified
6.7EPSS 0.002
CVE-2021-35092
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-35098
Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-35118
An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-35120
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-30324
Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-02-11 · Modified
6.7EPSS 0.001
CVE-2021-30325
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-02-11 · Modified
6.7EPSS 0.001
CVE-2024-49848
Use After Free in DSP Service
Published 2025-04-07 · Analyzed
6.7EPSS 0.001
CVE-2022-25654
Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
Published 2022-09-16 · Modified
6.7EPSS 0.001
CVE-2021-30299
Improper Input Validation in Audio
Published 2024-11-22 · Analyzed
6.7EPSS 0.001
CVE-2022-25666
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-10-19 · Modified
6.7EPSS 0.001
CVE-2024-23379
Double Free in DSP Services
Published 2024-10-07 · Analyzed
6.7EPSS 0.001
CVE-2021-30313
Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-01-13 · Modified
6.7EPSS 0.001
CVE-2024-53015
Use After Free in Computer Vision
Published 2025-06-03 · Analyzed
6.6EPSS 0.001
CVE-2025-47333
Use After Free in HLOS
Published 2026-01-06 · Analyzed
6.6EPSS 0.001
CVE-2021-1960
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-09-09 · Modified
6.5EPSS 0.002
CVE-2021-30348
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2022-01-03 · Modified
6.5EPSS 0.002
CVE-2021-1957
Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2021-09-09 · Modified
6.5EPSS 0.001
CVE-2024-43056
Buffer Over-read in Hypervisor
Published 2025-03-03 · Analyzed
6.5EPSS 0.001
CVE-2025-21465
Out-of-bounds Read in Core
Published 2025-08-06 · Analyzed
6.5EPSS 0.001
CVE-2020-11220
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-03-17 · Modified
6.4EPSS 0.001
CVE-2020-11230
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2021-03-17 · Modified
6.4EPSS 0.001
CVE-2025-59610
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
Published 2026-06-01 · Analyzed
6.4EPSS 0.001
CVE-2021-1904
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-09-08 · Modified
6.2EPSS 0.005
CVE-2022-25664
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-10-12 · Modified
6.2EPSS 0.002
CVE-2021-1929
Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2021-09-08 · Modified
6.2EPSS 0.002
CVE-2021-30314
Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-01-13 · Modified
6.2EPSS 0.001
CVE-2021-35079
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-06-14 · Modified
6.2EPSS 0.001
CVE-2022-22075
Information Exposure in Graphics
Published 2023-03-07 · Modified
6.2EPSS 0.001
CVE-2023-21624
Information Exposure in DSP Services
Published 2023-07-04 · Modified
6.2EPSS 0.001
CVE-2024-45551
Weak Authentication in HLOS
Published 2025-04-07 · Analyzed
6.2EPSS 0.001
CVE-2021-35135
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-09-02 · Modified
6.2EPSS 0.001
CVE-2023-28554
Buffer Over-read in Qualcomm IPC
Published 2023-11-07 · Modified
6.1EPSS 0.001
CVE-2023-28566
Buffer Over-read in WLAN HAL
Published 2023-11-07 · Modified
6.1EPSS 0.001
CVE-2023-28568
Buffer Over-read in WLAN HAL
Published 2023-11-07 · Modified
6.1EPSS 0.001
CVE-2023-28571
Buffer Over-read in WLAN HOST
Published 2023-10-03 · Modified
6.1EPSS 0.001
CVE-2023-43528
Buffer Over-read in Audio
Published 2024-05-06 · Analyzed
6.1EPSS 0.001
CVE-2024-33067
Buffer Over-read in Audio
Published 2025-01-06 · Analyzed
6.1EPSS 0.001
CVE-2025-47331
Buffer Over-read in Video
Published 2026-01-06 · Analyzed
6.1EPSS 0.001
CVE-2022-25722
Information Exposure in DSP Services
Published 2023-01-06 · Modified
6.0EPSS 0.001
← Prev10 / 11Next →