
CVE-2025-21448 – Buffer Over-read in WLAN Firmware
https://notcve.org/view.php?id=CVE-2025-21448
07 Apr 2025 — Transient DOS may occur while parsing SSID in action frames. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21434 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2025-21434
07 Apr 2025 — Transient DOS may occur while parsing EHT operation IE or EHT capability IE. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21430 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2025-21430
07 Apr 2025 — Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21429 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2025-21429
07 Apr 2025 — Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21428 – Buffer Over-read in WLAN Host
https://notcve.org/view.php?id=CVE-2025-21428
07 Apr 2025 — Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2024-49848 – Use After Free in DSP Service
https://notcve.org/view.php?id=CVE-2024-49848
07 Apr 2025 — Memory corruption while processing multiple IOCTL calls from HLOS to DSP. A FASTRPC_ATTR_KEEP_MAP logic bug allows fastrpc_internal_munmap_fd to concurrently free in-use mappings leading to a use-after-free condition. • https://packetstorm.news/files/id/190388 • CWE-416: Use After Free •

CVE-2024-45556 – Improper Access Control for Register Interface in TZ Firmware
https://notcve.org/view.php?id=CVE-2024-45556
07 Apr 2025 — Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-1262: Improper Access Control for Register Interface •

CVE-2024-45552 – Buffer Over-read in Data Network Stack & Connectivity
https://notcve.org/view.php?id=CVE-2024-45552
07 Apr 2025 — Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2024-45551 – Weak Authentication in HLOS
https://notcve.org/view.php?id=CVE-2024-45551
07 Apr 2025 — Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-1390: Weak Authentication •

CVE-2024-43066 – Use After Free in HLOS
https://notcve.org/view.php?id=CVE-2024-43066
07 Apr 2025 — Memory corruption while handling file descriptor during listener registration/de-registration. • https://docs.qualcomm.com/product/publicresources/securitybulletin/april-2025-bulletin.html • CWE-416: Use After Free •