📦 Qca9367 Firmware

by Qualcomm

🔍 What is Qca9367 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-43551

CRITICAL CVSS 9.1 Jun 3, 2024

This vulnerability allows a rogue LTE base station to bypass authentication during network attachment, enabling man-in-the-middle attacks. It affects mobile devices with Qualcomm chipsets that handle ...

CVE-2022-40510

CRITICAL CVSS 9.8 Aug 8, 2023

CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause denial of service. The vulnerability affects devices ...

CVE-2022-25651

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm Bluetooth chips. It affects devices using Snapdragon processors with B...

CVE-2021-35104

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the FLAC audio header parser. Attackers can trigger this...

CVE-2021-30341

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows improper buffer size validation in DSM packets received by Qualcomm Snapdragon chipsets, leading to memory corruption. Attackers can exploit this to execute arbitrary code or...

CVE-2021-30351

CRITICAL CVSS 9.8 Jan 3, 2022

CVE-2021-30351 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets, allowing attackers to execute arbitrary code or cause denial of service by exploiting improper validation du...

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1975

CRITICAL CVSS 9.8 Nov 12, 2021

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses. Attackers can exploit this to execute arbitrary c...

CVE-2021-1976

CRITICAL CVSS 9.8 Sep 17, 2021

This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (peer-to-peer) device address validation. Attackers...

CVE-2021-1972

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P search functionality. Attackers can exploit improper va...

CVE-2021-1916

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting a buffer underflow in Qualcomm Snapdragon chipsets. It affects numerous Qualcomm-powered devices ...

CVE-2021-1920

CRITICAL CVSS 9.8 Sep 8, 2021

CVE-2021-1920 is an integer underflow vulnerability in Qualcomm Snapdragon chipsets' RTCP packet handling that allows remote code execution. Attackers can send specially crafted RTCP packets to trigge...

CVE-2020-11159

CRITICAL CVSS 9.1 Jun 9, 2021

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing WPA/RSN information elements in Wi-Fi beacon and response frames. Attackers can exploit this to read...

CVE-2020-11227

CRITICAL CVSS 9.8 Mar 17, 2021

This vulnerability allows attackers to write data beyond allocated memory boundaries while parsing RTT/TTY packets in Qualcomm Snapdragon chipsets. It affects numerous Snapdragon-powered devices acros...

CVE-2020-11299

CRITICAL CVSS 9.8 Mar 17, 2021

A buffer overflow vulnerability in Qualcomm Snapdragon video processing allows attackers to execute arbitrary code by playing specially crafted video files. This affects numerous Snapdragon-powered de...

CVE-2020-11188

CRITICAL CVSS 9.1 Mar 17, 2021

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing SDP values without proper NULL termination checks. It allows attackers to read memory beyond allocated buffers, po...

CVE-2020-11190

CRITICAL CVSS 9.1 Mar 17, 2021

CVE-2020-11190 is a buffer over-read vulnerability in Qualcomm Snapdragon chipsets that allows attackers to read memory beyond allocated buffers when parsing SDP values. This can lead to information d...

CVE-2020-11166

CRITICAL CVSS 9.1 Mar 17, 2021

This vulnerability allows an attacker to cause an out-of-bounds read exception by sending specially crafted ROHC headers with excessive padding to affected Qualcomm Snapdragon devices. Successful expl...

CVE-2020-11272

CRITICAL CVSS 9.8 Feb 22, 2021

This is a use-after-free vulnerability in Qualcomm Snapdragon chipsets that allows attackers to execute arbitrary code or cause denial of service. It affects a wide range of Snapdragon-powered devices...

CVE-2020-11276

CRITICAL CVSS 9.1 Feb 22, 2021

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets that occurs when processing Wi-Fi P2P (Peer-to-Peer) information elements and NOA (Notice of Absence) attributes in beacon and ...

CVE-2026-21385

HIGH CVSS 7.8 Mar 2, 2026

This CVE describes a memory corruption vulnerability in alignment-based memory allocation functions. Attackers can exploit this to execute arbitrary code or cause denial of service. The vulnerability ...

CVE-2025-47385

HIGH CVSS 7.8 Mar 2, 2026

This vulnerability allows memory corruption when accessing the trusted execution environment (TEE) without proper privilege checks. Attackers could potentially execute arbitrary code or cause denial o...

CVE-2025-47381

HIGH CVSS 7.8 Mar 2, 2026

This vulnerability allows memory corruption when multiple processes concurrently access shared buffers through IOCTL calls in Qualcomm drivers. Attackers could potentially execute arbitrary code or ca...

CVE-2025-47376

HIGH CVSS 7.8 Mar 2, 2026

This vulnerability allows memory corruption when multiple processes concurrently access a shared buffer during IOCTL calls in Qualcomm components. Attackers could potentially execute arbitrary code or...

CVE-2025-47382

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption in the boot loader when loading invalid firmware, potentially enabling attackers to execute arbitrary code or cause denial of service. It affects devices us...

CVE-2025-47320

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption during MFC channel configuration while playing music, potentially enabling arbitrary code execution. It affects devices with Qualcomm chipsets that use the ...

CVE-2025-27053

HIGH CVSS 7.8 Oct 9, 2025

This vulnerability allows memory corruption in Qualcomm's PlayReady APP implementation when processing TA commands, potentially enabling arbitrary code execution. It affects devices with Qualcomm chip...

CVE-2025-27052

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption in the diag component when processing data packets from Unix clients. Attackers could potentially execute arbitrary code or cause denial of service on affec...

CVE-2025-27043

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption in Qualcomm video firmware when processing manipulated payloads. Attackers could potentially execute arbitrary code or cause denial of service. Affects devi...

CVE-2024-45564

HIGH CVSS 7.8 May 6, 2025

CVE-2024-45564 is a use-after-free vulnerability in Qualcomm server components where concurrent access to server info objects can cause memory corruption due to incorrect reference count updates. This...

CVE-2025-21429

HIGH CVSS 7.5 Apr 7, 2025

This vulnerability allows memory corruption during Wi-Fi connection establishment between a station (STA) and access point (AP) when initiating an ADD TS (Traffic Stream) request. Attackers could pote...

CVE-2024-53027

HIGH CVSS 7.5 Mar 3, 2025

This vulnerability in Qualcomm components allows a denial-of-service attack when processing country information elements. It affects devices using Qualcomm chipsets, potentially causing temporary serv...

CVE-2024-43060

HIGH CVSS 7.8 Mar 3, 2025

This CVE describes a memory corruption vulnerability in Qualcomm's voice activation system when sound model parameters are transferred from the HLOS (High-Level Operating System) to the ADSP (Audio Di...

CVE-2024-43057

HIGH CVSS 7.8 Mar 3, 2025

CVE-2024-43057 is a use-after-free vulnerability in the Glink Linux driver that allows memory corruption when processing commands. This could enable local privilege escalation or denial of service att...

CVE-2024-49838

HIGH CVSS 8.2 Feb 3, 2025

This vulnerability allows attackers to read sensitive memory contents when parsing malformed OCI (Oracle Call Interface) information elements with invalid length fields. It affects systems using Qualc...

CVE-2024-38423

HIGH CVSS 7.8 Nov 4, 2024

This vulnerability allows memory corruption during GPU page table switching in Qualcomm GPU drivers. Attackers could potentially execute arbitrary code or cause denial of service. Affects devices usin...

CVE-2024-33049

HIGH CVSS 7.5 Oct 7, 2024

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with specific Extension element parameters. It affects systems using Qualc...

CVE-2024-33051

HIGH CVSS 7.5 Sep 2, 2024

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in affected Wi-Fi systems by sending specially crafted beacon frames with malformed TIM (Traffic Indication Map) Info...

CVE-2024-33045

HIGH CVSS 8.4 Sep 2, 2024

This vulnerability allows memory corruption when the BTFM client sends new messages over Slimbus to the ADSP in Qualcomm chipsets. Attackers could potentially execute arbitrary code or cause denial of...

CVE-2024-33028

HIGH CVSS 8.4 Aug 5, 2024

This CVE describes a use-after-free vulnerability in Qualcomm graphics drivers where a fence object may still be accessed after being released during timeline destruction. This memory corruption could...

CVE-2024-33022

HIGH CVSS 8.4 Aug 5, 2024

This vulnerability allows memory corruption in the HGSL driver when allocating memory, potentially leading to arbitrary code execution or system crashes. It affects devices using Qualcomm chipsets wit...

CVE-2024-33012

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Wi-Fi systems by sending specially crafted beacon frames with malformed MBSSID information elements. It affects devi...

CVE-2024-33014

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted beacon or probe response frames containing malformed ESP IE (Extended Service Period Information E...

CVE-2024-33010

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in Wi-Fi beacon frames. It affects systems using Qual...

CVE-2024-21479

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a buffer over-read (CWE-126) in Apple Lossless Audio Codec (ALAC) processing. When a specially crafted AL...

CVE-2024-23368

HIGH CVSS 7.8 Jul 1, 2024

This CVE describes a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that could allow attackers to execute arbitrary code or cause denial of service. The vulnerability aff...

CVE-2024-21468

HIGH CVSS 8.4 Apr 1, 2024

CVE-2024-21468 is a use-after-free vulnerability in Qualcomm GPU drivers where failed memory unmapping operations can lead to memory corruption. This allows attackers to potentially execute arbitrary ...

CVE-2023-33066

HIGH CVSS 8.4 Mar 4, 2024

This vulnerability allows memory corruption in Qualcomm audio drivers when processing RT proxy port register operations. Attackers could potentially execute arbitrary code or cause denial of service o...

CVE-2023-43511

HIGH CVSS 7.5 Jan 2, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm WLAN firmware by sending specially crafted IPv6 packets with IPPROTO_NONE as the next header in extension h...

CVE-2023-33017

HIGH CVSS 7.8 Dec 5, 2023

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices with vulnerable firmware, potentially allowing attac...

CVE-2023-28551

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability allows memory corruption in Qualcomm modem UTILS when processing Diag commands with arbitrary address values. Attackers could potentially execute arbitrary code or cause denial of s...

CVE-2023-24848

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows information disclosure in Qualcomm data modems during VoLTE calls when an undefined RTCP FB line value is processed. Attackers could potentially access sensitive information ...

CVE-2023-22385

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows memory corruption in Qualcomm data modem chipsets during mobile-originated or mobile-terminated VoLTE calls. Attackers could potentially execute arbitrary code or cause denia...

CVE-2023-28565

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing command streams through WMI interfaces. Attackers could potentially execute arbitrary co...

CVE-2023-33019

HIGH CVSS 7.5 Sep 5, 2023

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in WLAN hosts by sending malformed Channel Switch Announcement (CSA) frames with invalid channel information. It affe...

CVE-2023-21626

HIGH CVSS 7.1 Aug 8, 2023

This cryptographic vulnerability in Qualcomm's HLOS (High-Level Operating System) allows improper authentication during key velocity checks when multiple keys are involved. It affects devices using Qu...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2023-21628

HIGH CVSS 8.4 Jun 6, 2023

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing specific wireless commands. Attackers could potentially execute arbitrary code or cause ...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2023-21666

HIGH CVSS 8.4 May 2, 2023

CVE-2023-21666 is a memory corruption vulnerability in Qualcomm's Adreno GPU driver (KGSL) that allows attackers to access sensitive data from graphics memory pools. This affects Android devices with ...

CVE-2025-47330

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to vulnerable systems. It affects devices using Qualcomm video firmware co...

CVE-2025-47331

MEDIUM CVSS 6.1 Jan 7, 2026

This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects devices using vulnerable Qualcomm chipsets, potent...

CVE-2025-47333

MEDIUM CVSS 6.6 Jan 7, 2026

This vulnerability allows memory corruption in Qualcomm's cryptographic driver when handling buffer mapping operations. Attackers could potentially execute arbitrary code or cause denial of service. A...

CVE-2025-27064

MEDIUM CVSS 6.1 Nov 4, 2025

This vulnerability allows information disclosure through the diagHal interface when registering commands from clients. It affects Qualcomm devices using the vulnerable diag component, potentially expo...

CVE-2025-27041

MEDIUM CVSS 5.5 Oct 9, 2025

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to affected Qualcomm devices. The issue occurs during video packet process...

CVE-2025-27030

MEDIUM CVSS 6.1 Sep 24, 2025

This CVE-2025-27030 vulnerability allows unauthorized information disclosure when calibration data is invoked from user space to update firmware size. It affects Qualcomm devices and systems using vul...

CVE-2025-21472

MEDIUM CVSS 5.5 Aug 6, 2025

This vulnerability allows unauthorized access to sensitive information when logs are captured, as eSE debug messages containing potentially sensitive data are logged. It affects systems using Qualcomm...

CVE-2024-53013

MEDIUM CVSS 6.6 Jun 3, 2025

This CVE describes a buffer overflow vulnerability in Qualcomm's voice call registration processing that could allow memory corruption. Attackers could potentially execute arbitrary code or cause deni...

CVE-2024-45581

MEDIUM CVSS 6.6 May 6, 2025

This vulnerability allows memory corruption during sound model registration for voice activation in Qualcomm audio kernel drivers. Attackers could potentially execute arbitrary code with kernel privil...

CVE-2024-45544

MEDIUM CVSS 6.6 Apr 7, 2025

This vulnerability allows memory corruption through improper handling of IOCTL calls when adding route entries in Qualcomm hardware. Attackers could potentially execute arbitrary code or cause denial ...

CVE-2024-45540

MEDIUM CVSS 6.6 Apr 7, 2025

This vulnerability allows memory corruption through improper handling of IOCTL map buffer requests from userspace. Attackers could potentially execute arbitrary code or cause denial of service. This a...

CVE-2024-38426

MEDIUM CVSS 5.4 Mar 3, 2025

This vulnerability in Qualcomm UE (User Equipment) authentication processing allows improper authentication that could lead to information disclosure. It affects devices using Qualcomm chipsets with v...

CVE-2024-38416

MEDIUM CVSS 6.1 Feb 3, 2025

CVE-2024-38416 is an information disclosure vulnerability in Qualcomm audio components that allows attackers to access sensitive memory contents during audio playback. This affects devices using Qualc...

CVE-2024-33030

MEDIUM CVSS 6.7 Nov 4, 2024

This CVE describes a memory corruption vulnerability in Qualcomm's IPC frequency table parameter parsing for LPLH (likely Low Power Low Hardware). When processing parameters larger than expected, it c...

CVE-2024-23370

MEDIUM CVSS 6.7 Oct 7, 2024

This vulnerability allows memory corruption when two processes concurrently create and destroy the same HAB virtual channel via IOCTL calls. It affects systems using Qualcomm hardware with HAB functio...