CVE-2025-47404
Published May 4, 2026Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Vendor/product archive
26 CVEs tagged to qualcomm / qcc710 — 3 Critical, 17 High, 6 Medium, 0 Low, 0 Unrated.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
Memory corruption while selecting the PLMN from SOR failed list.
Information disclosure while opening a fastrpc session when domain is not sanitized.
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
Memory corruption while decoding of OTA messages from T3448 IE.
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Transient DOS may occur while processing the country IE.
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Memory corruption while processing the update SIM PB records request.
Memory corruption while processing concurrent IOCTL calls.
Cryptographic issue while parsing RSA keys in COBR format.
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
Transient DOS while processing CAG info IE received from NW.
Transient DOS while processing IE fragments from server during DTLS handshake.
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
Information disclosure in Modem while processing SIB5.
Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.