📦 Qcn9074 Firmware
by Qualcomm
🔍 What is Qcn9074 Firmware?
Description coming soon...
🛡️ Security Overview
Click on a severity to filter vulnerabilities
⚠️ Known Vulnerabilities
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted ML IE frames to affected Qualcomm devices. It affects systems using Qualcom...
This vulnerability allows memory corruption when log files are redirected to arbitrary file locations with arbitrary names. It affects systems using Qualcomm components that handle log redirection fun...
This vulnerability allows memory corruption when redirecting log files to arbitrary locations with arbitrary filenames in Qualcomm components. It affects devices using Qualcomm chipsets and software. ...
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption when processing specially crafted MBSSID beacon frames containing multiple subelem...
CVE-2023-28578 is a memory corruption vulnerability in Qualcomm Core Services that occurs when removing a single event listener. This allows attackers to potentially execute arbitrary code or cause de...
This CVE describes a memory corruption vulnerability in Qualcomm Core components that could allow attackers to execute arbitrary code or cause denial of service. It affects devices using vulnerable Qu...
This vulnerability allows memory corruption in the TrustZone Secure OS when requesting memory allocation from the Trusted Application region. It affects Qualcomm chipsets with TrustZone technology, po...
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm Wi-Fi chipsets. It affects devices using vulnerable Qualcomm wireless ...
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm WLAN firmware when parsing specially crafted NAN management frames. It...
This vulnerability allows memory corruption in Qualcomm WLAN firmware during PMK cache operations, potentially enabling remote code execution. It affects devices with vulnerable Qualcomm WLAN chipsets...
CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause denial of service. The vulnerability affects devices ...
CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in WLAN firmware. It affects Qualcomm chipsets used ...
CVE-2022-33279 is a critical stack-based buffer overflow vulnerability in Qualcomm WLAN firmware that allows remote code execution when processing malicious WNM (Wireless Network Management) frames. A...
This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the FLAC audio header parser. Attackers can trigger this...
CVE-2021-30351 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets, allowing attackers to execute arbitrary code or cause denial of service by exploiting improper validation du...
This vulnerability is an integer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of service. It affects multiple Snapdragon product lines ...
This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...
This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (peer-to-peer) device address validation. Attackers...
This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P search functionality. Attackers can exploit improper va...
This vulnerability involves memory corruption during HDCP session deinitialization, potentially allowing attackers to execute arbitrary code or cause denial of service. It affects systems using Qualco...
This vulnerability involves memory corruption while processing a GP command response in Qualcomm components, potentially allowing attackers to execute arbitrary code or cause denial of service. It aff...
This vulnerability allows memory corruption during SCM (System Control Manager) calls in Qualcomm components, potentially enabling privilege escalation or remote code execution. It affects devices usi...
This vulnerability allows memory corruption in Qualcomm's PlayReady APP implementation when processing TA commands, potentially enabling arbitrary code execution. It affects devices with Qualcomm chip...
This vulnerability allows attackers to cause a denial of service (DoS) condition by sending specially crafted EPTM test control messages. It affects systems using Qualcomm components that process thes...
This CVE describes a use-after-free vulnerability in Qualcomm camera kernel drivers where improper reference counting of CPU buffers during config_dev IOCTL processing can lead to memory corruption. A...
This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a flaw in the Neighbor Discovery Protocol (NDP) instance creation process. It affects systems using Qualc...
This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted frame with a malformed shared-key descriptor to affected Qualcomm wireless components. The attac...
This vulnerability allows memory corruption in Qualcomm video firmware when processing manipulated payloads. Attackers could potentially execute arbitrary code or cause denial of service. Affects devi...
This vulnerability allows a denial-of-service (DoS) condition in Qualcomm wireless LAN (WLAN) chipsets when processing vendor-specific information elements in BTM (BSS Transition Management) request f...
This vulnerability allows attackers to cause a Denial of Service (DoS) condition by sending specially crafted tone measurement responses that exceed buffer boundaries. It affects Qualcomm chipsets and...
This vulnerability allows an attacker to cause a Denial of Service (DoS) condition by sending specially crafted beacon frames containing EHT operation information elements. It affects systems using Qu...
CVE-2024-45564 is a use-after-free vulnerability in Qualcomm server components where concurrent access to server info objects can cause memory corruption due to incorrect reference count updates. This...
This vulnerability allows memory corruption during Wi-Fi connection establishment between a station (STA) and access point (AP) when initiating an ADD TS (Traffic Stream) request. Attackers could pote...
This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm NPU driver APIs that can be triggered through concurrent calls, leading to memory corruption. It affects devices with Qualcomm c...
CVE-2024-43057 is a use-after-free vulnerability in the Glink Linux driver that allows memory corruption when processing commands. This could enable local privilege escalation or denial of service att...
This vulnerability allows memory corruption during Wi-Fi management frame processing due to a mismatch in T2LM (Target Wake Time Link Management) information elements. Attackers within Wi-Fi range cou...
This vulnerability allows memory corruption through improper handling of memory map information in IOCTL calls. Attackers could potentially execute arbitrary code or cause denial of service. This affe...
This vulnerability in Qualcomm Wi-Fi drivers allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted packets. The driver fails to properly validate the length of per...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with malformed Multi-Link (ML) Information Elements. It affects devices us...
This vulnerability allows memory corruption during GPU page table switching in Qualcomm GPU drivers. Attackers could potentially execute arbitrary code or cause denial of service. Affects devices usin...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in Wi-Fi beacon frames. It affects devices with Qua...
This vulnerability allows attackers to read sensitive information from Wi-Fi chipsets when parsing Multi-Link Device (MLD) information elements. It affects devices with Qualcomm Wi-Fi chipsets that ha...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with specific Extension element parameters. It affects systems using Qualc...
This vulnerability allows memory corruption when two threads simultaneously map and unmap a single node in Qualcomm components. Successful exploitation could lead to arbitrary code execution or system...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon or probe response frames to affected Wi-Fi devices. The issue occurs during parsi...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in affected Wi-Fi systems by sending specially crafted beacon frames with malformed TIM (Traffic Indication Map) Info...
This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted Wi-Fi beacon frames with malformed Multi-Link (ML) Information Elements. It affects devices using ...
This vulnerability allows an attacker to cause a denial-of-service condition in affected Qualcomm Wi-Fi components by sending specially crafted probe response or association response frames with malfo...
This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted TID-to-link mapping action frames to affected Wi-Fi devices. The vulnerability affects Q...
This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Wi-Fi systems by sending specially crafted beacon frames with malformed MBSSID information elements. It affects devi...
This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted beacon or probe response frames containing malformed ESP IE (Extended Service Period Information E...
This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in Wi-Fi beacon frames. It affects systems using Qual...
This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a buffer over-read (CWE-126) in Apple Lossless Audio Codec (ALAC) processing. When a specially crafted AL...
This CVE describes a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that could allow attackers to execute arbitrary code or cause denial of service. The vulnerability aff...
This vulnerability allows a denial-of-service attack when loading Trusted Application (TA) ELF files on Qualcomm chipsets. It affects devices using Qualcomm processors with vulnerable firmware. Attack...
CVE-2024-21468 is a use-after-free vulnerability in Qualcomm GPU drivers where failed memory unmapping operations can lead to memory corruption. This allows attackers to potentially execute arbitrary ...
This CVE describes a memory corruption vulnerability in the SPS Application's sorter Trusted Application (TA) when requesting public keys. Successful exploitation could allow attackers to execute arbi...
This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm WLAN systems by sending a large number of malformed authentication frames with invalid transaction sequence...
This vulnerability allows memory corruption in Qualcomm audio drivers when processing RT proxy port register operations. Attackers could potentially execute arbitrary code or cause denial of service o...
This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects devices using vulnerable Qualcomm chipsets, potent...
This vulnerability allows attackers to access sensitive information by exploiting improper handling of system calls with invalid parameters. It affects systems using Qualcomm chipsets with vulnerable ...
This vulnerability allows information disclosure through the diagHal interface when registering commands from clients. It affects Qualcomm devices using the vulnerable diag component, potentially expo...
This CVE describes an information disclosure vulnerability in Qualcomm hypervisor logs that could expose sensitive system information. The vulnerability affects devices using Qualcomm chipsets with vu...
This CVE-2025-27030 vulnerability allows unauthorized information disclosure when calibration data is invoked from user space to update firmware size. It affects Qualcomm devices and systems using vul...
This vulnerability allows attackers to read sensitive information from image processing operations by manipulating offset and size parameters. It affects systems using Qualcomm components with vulnera...
This vulnerability allows attackers to read sensitive information from memory when processing specially crafted MBN files. It affects systems using Qualcomm chipsets that process MBN files, potentiall...
This CVE describes a buffer overflow vulnerability in Qualcomm's voice call registration processing that could allow memory corruption. Attackers could potentially execute arbitrary code or cause deni...
This vulnerability allows memory corruption through improper handling of IOCTL calls when adding route entries in Qualcomm hardware. Attackers could potentially execute arbitrary code or cause denial ...
This vulnerability allows memory corruption through improper handling of IOCTL map buffer requests from userspace. Attackers could potentially execute arbitrary code or cause denial of service. This a...
CVE-2024-38416 is an information disclosure vulnerability in Qualcomm audio components that allows attackers to access sensitive memory contents during audio playback. This affects devices using Qualc...
CVE-2024-33053 is a use-after-free vulnerability in Qualcomm's CVP buffer management that allows memory corruption when multiple threads simultaneously unregister buffers. This could lead to arbitrary...
This CVE describes a memory corruption vulnerability in Qualcomm camera drivers where a user-space variable is used for kernel memory allocation, potentially leading to buffer overflows or invalid mem...
This CVE describes a memory corruption vulnerability in Qualcomm components where asynchronous modification of shared memory by user applications while the kernel is accessing it can lead to system in...
This vulnerability allows information disclosure when handling beacon probe frames during scan entry generation on client devices. It affects devices with Qualcomm Wi-Fi chipsets that process wireless...
This vulnerability allows information disclosure when parsing sub-IE length during new IE generation in Qualcomm components. It affects devices using Qualcomm chipsets with vulnerable firmware. Attack...
This vulnerability allows information disclosure when handling Multi-link Information Elements in Wi-Fi beacon frames. It affects devices with Qualcomm Wi-Fi chipsets that process these frames, potent...
This vulnerability allows attackers to access sensitive information from memory when parsing dts header atoms in video files. It affects devices using Qualcomm chipsets with vulnerable multimedia proc...
This CVE describes a use-after-free vulnerability in Qualcomm components where registering multiple listeners with the same file descriptor can cause memory corruption. This affects devices using Qual...