Qualcomm Cologne Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Qualcomm Cologne Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (59)
CVE-2026-25289 — CVSS 9.6 (critical): Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25283 — CVSS 8.8 (high): Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25282 — CVSS 7.9 (high): Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25290 — CVSS 7.8 (high): Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2025-47389 — CVSS 7.8 (high): Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2025-59604 — CVSS 7.8 (high): Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-59606 — CVSS 7.8 (high): Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2026-25271 — CVSS 7.8 (high): Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
CVE-2026-25260 — CVSS 7.8 (high): Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVE-2026-21372 — CVSS 7.8 (high): Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
CVE-2026-21373 — CVSS 7.8 (high): Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374 — CVSS 7.8 (high): Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
CVE-2026-21375 — CVSS 7.8 (high): Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21376 — CVSS 7.8 (high): Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21378 — CVSS 7.8 (high): Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21382 — CVSS 7.8 (high): Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-24073 — CVSS 7.8 (high): Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2026-24075 — CVSS 7.8 (high): Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and…
CVE-2026-24074 — CVSS 7.8 (high): Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVE-2026-21381 — CVSS 7.6 (high): Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network…
CVE-2026-21367 — CVSS 7.6 (high): Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2026-25275 — CVSS 7.5 (high): Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24081 — CVSS 7.4 (high): Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2025-47402 — CVSS 6.5 (medium): Transient DOS when processing a received frame with an excessively large authentication information element.
CVE-2025-47403 — CVSS 6.5 (medium): Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.