Vulnerabilities (CVE)

Filtered by vendor Qualcomm Subscribe
Filtered by product Qcn9003 Firmware
Total 65 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-27073 1 Qualcomm 340 Ar8035, Ar8035 Firmware, Csr8811 and 337 more 2025-08-20 N/A 7.5 HIGH
Transient DOS while creating NDP instance.
CVE-2023-33047 1 Qualcomm 356 Ar8035, Ar8035 Firmware, Ar9380 and 353 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing no-inherit IES.
CVE-2023-33098 1 Qualcomm 526 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 523 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
CVE-2023-33062 1 Qualcomm 580 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 577 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing a BTM request.
CVE-2025-21446 1 Qualcomm 480 Ar8035, Ar8035 Firmware, Ar9380 and 477 more 2025-08-11 N/A 7.5 HIGH
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2023-33109 1 Qualcomm 620 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 617 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2023-24854 1 Qualcomm 326 215, 215 Firmware, Ar8035 and 323 more 2025-08-11 N/A 7.8 HIGH
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
CVE-2025-27042 1 Qualcomm 690 215 Mobile, 215 Mobile Firmware, 315 5g Iot Modem and 687 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing video packets received from video firmware.
CVE-2023-43536 1 Qualcomm 618 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 615 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parse fils IE with length equal to 1.
CVE-2025-27061 1 Qualcomm 688 315 5g Iot, 315 5g Iot Firmware, Aqt1000 and 685 more 2025-08-11 N/A 7.8 HIGH
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2023-33027 1 Qualcomm 656 315 5g Iot Modem, 315 5g Iot Modem Firmware, 8098 and 653 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing rsn ies.
CVE-2023-33080 1 Qualcomm 732 315 5g Iot Modem, 315 5g Iot Modem Firmware, 8098 and 729 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-43511 1 Qualcomm 712 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9206 Lte Modem and 709 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-22386 1 Qualcomm 402 215, 215 Firmware, Ar8035 and 399 more 2025-08-11 N/A 7.8 HIGH
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
CVE-2023-43522 1 Qualcomm 572 Aqt1000, Aqt1000 Firmware, Ar8035 and 569 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2023-33089 1 Qualcomm 456 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 453 more 2025-08-11 N/A 7.5 HIGH
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
CVE-2023-33028 1 Qualcomm 352 Ar8035, Ar8035 Firmware, Ar9380 and 349 more 2025-08-11 N/A 9.8 CRITICAL
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
CVE-2023-43513 1 Qualcomm 534 315 5g Iot Modem, 315 5g Iot Modem Firmware, Apq8017 and 531 more 2025-08-11 N/A 7.8 HIGH
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
CVE-2023-33026 1 Qualcomm 390 Ar8035, Ar8035 Firmware, Ar9380 and 387 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in WLAN Firmware while parsing a NAN management frame.
CVE-2023-28578 1 Qualcomm 680 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 677 more 2025-08-11 N/A 9.3 CRITICAL
Memory corruption in Core Services while executing the command for removing a single event listener.