CVE-2025-24857
Published Dec 10, 2025Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, I…
Vendor/product archive
52 CVEs tagged to qualcomm / ipq5018 — 10 Critical, 37 High, 5 Medium, 0 Low, 0 Unrated.
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, I…
Memory Corruption in Core Platform while printing the response buffer in log.
Memory corruption in Core Platform while printing the response buffer in log.
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
Transient DOS due to improper input validation in WLAN Host.
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Memory corruption due to improper access control in Qualcomm IPC.
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
Information exposure in DSP services due to improper handling of freeing memory
Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wi…
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking