
CVE-2025-27066 – Reachable Assertion in WLAN Firmware
https://notcve.org/view.php?id=CVE-2025-27066
06 Aug 2025 — Transient DOS while processing an ANQP message. DOS transitorio al procesar un mensaje ANQP. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html • CWE-617: Reachable Assertion •

CVE-2025-21465 – Out-of-bounds Read in Core
https://notcve.org/view.php?id=CVE-2025-21465
06 Aug 2025 — Information disclosure while processing the hash segment in an MBN file. Divulgación de información durante el procesamiento del segmento hash en un archivo MBN. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html • CWE-125: Out-of-bounds Read •

CVE-2025-21464 – Out-of-bounds Read in Core
https://notcve.org/view.php?id=CVE-2025-21464
06 Aug 2025 — Information disclosure while reading data from an image using specified offset and size parameters. Divulgación de información durante la lectura de datos de una imagen utilizando parámetros de tamaño y desplazamiento especificados. • https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html • CWE-125: Out-of-bounds Read •

CVE-2025-27061 – Out-of-bounds Write in Video
https://notcve.org/view.php?id=CVE-2025-27061
08 Jul 2025 — Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-787: Out-of-bounds Write •

CVE-2025-27042 – Incorrect Calculation of Buffer Size in Video
https://notcve.org/view.php?id=CVE-2025-27042
08 Jul 2025 — Memory corruption while processing video packets received from video firmware. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-131: Incorrect Calculation of Buffer Size •

CVE-2025-21454 – Buffer Over-read in WLAN Embedded SW
https://notcve.org/view.php?id=CVE-2025-21454
08 Jul 2025 — Transient DOS while processing received beacon frame. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21449 – Buffer Over-read in WLAN Embedded SW
https://notcve.org/view.php?id=CVE-2025-21449
08 Jul 2025 — Transient DOS may occur while processing malformed length field in SSID IEs. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21433 – NULL Pointer Dereference in SPS-HLOS
https://notcve.org/view.php?id=CVE-2025-21433
08 Jul 2025 — Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-476: NULL Pointer Dereference •

CVE-2025-21427 – Buffer Over-read in Data HLOS - LNX
https://notcve.org/view.php?id=CVE-2025-21427
08 Jul 2025 — Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-126: Buffer Over-read •

CVE-2025-21422 – Cryptographic Issues in Automotive
https://notcve.org/view.php?id=CVE-2025-21422
08 Jul 2025 — Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. • https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html • CWE-310: Cryptographic Issues •