This page lists publicly disclosed CVE vulnerabilities affecting qualcomm mdm9640_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-47383 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | [email protected] | 7.2 | 0.13% | 2026-03-02 | 2026-06-17 |
| CVE-2025-47320 | Memory corruption while processing MFC channel configuration during music playback. | [email protected] | 7.8 | 0.07% | 2025-12-18 | 2026-06-17 |
| CVE-2025-27074 | Memory corruption while processing a GP command response. | [email protected] | 8.8 | 0.07% | 2025-11-03 | 2026-06-17 |
| CVE-2025-27053 | Memory corruption during PlayReady APP usecase while processing TA commands. | [email protected] | 7.8 | 0.08% | 2025-10-09 | 2026-06-17 |
| CVE-2025-47318 | Transient DOS while parsing the EPTM test control message to get the test pattern. | [email protected] | 7.5 | 0.19% | 2025-09-24 | 2026-06-17 |
| CVE-2025-21482 | Cryptographic issue while performing RSA PKCS padding decoding. | [email protected] | 7.1 | 0.08% | 2025-09-24 | 2026-06-17 |
| CVE-2025-21430 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | [email protected] | 7.5 | 0.21% | 2025-04-07 | 2026-06-17 |
| CVE-2025-21429 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | [email protected] | 7.5 | 0.21% | 2025-04-07 | 2026-06-17 |
| CVE-2025-21428 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | [email protected] | 7.5 | 0.21% | 2025-04-07 | 2026-06-17 |
| CVE-2024-53027 | Transient DOS may occur while processing the country IE. | [email protected] | 7.5 | 0.34% | 2025-03-03 | 2026-06-17 |
| CVE-2024-38426 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | [email protected] | 5.4 | 0.25% | 2025-03-03 | 2026-06-17 |
| CVE-2018-5852 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' | [email protected] | 8.4 | 0.06% | 2024-11-26 | 2026-06-16 |
| CVE-2018-11952 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. | [email protected] | 8.4 | 0.07% | 2024-11-26 | 2026-06-16 |
| CVE-2018-11922 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. | [email protected] | 9.8 | 0.17% | 2024-11-26 | 2026-06-16 |
| CVE-2017-9711 | Certain unprivileged processes are able to perform IOCTL calls. | [email protected] | 6.7 | 0.11% | 2024-11-22 | 2026-06-16 |
| CVE-2024-38422 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | [email protected] | 7.8 | 0.10% | 2024-11-04 | 2026-06-17 |
| CVE-2024-33051 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | [email protected] | 7.5 | 0.30% | 2024-09-02 | 2026-06-17 |
| CVE-2024-23353 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | [email protected] | 7.5 | 0.35% | 2024-08-05 | 2026-06-17 |
| CVE-2024-21461 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. | [email protected] | 8.4 | 0.14% | 2024-07-01 | 2026-06-17 |
| CVE-2023-43551 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | [email protected] | 9.1 | 0.26% | 2024-06-03 | 2026-06-17 |