Home › Vendors › Qualcomm › Sc8380xp FirmwareQualcomm Sc8380xp Firmware — known CVE vulnerabilities Every CVE whose affected-product data names Qualcomm Sc8380xp Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (200) CVE-2023-33045 — CVSS 9.8 (critical) : Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.CVE-2026-25289 — CVSS 9.6 (critical) : Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.CVE-2023-43538 — CVSS 9.3 (critical) : Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.CVE-2023-33072 — CVSS 9.3 (critical) : Memory corruption in Core while processing control functions.CVE-2023-28578 — CVSS 9.3 (critical) : Memory corruption in Core Services while executing the command for removing a single event listener.CVE-2023-28574 — CVSS 9.0 (critical) : Memory corruption in core services when Diag handler receives a command to configure event listeners.CVE-2024-38420 — CVSS 8.8 (high) : Memory corruption while configuring a Hypervisor based input virtual device.CVE-2025-21480 — CVSS 8.6 (high) — actively exploited : Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.CVE-2025-47345 — CVSS 8.4 (high) : Cryptographic issue may occur while encrypting license data.CVE-2023-43535 — CVSS 8.4 (high) : Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.CVE-2023-43554 — CVSS 8.4 (high) : Memory corruption while processing IOCTL handler in FastRPC.CVE-2023-43549 — CVSS 8.4 (high) : Memory corruption while processing TPC target power table in FTM TPC.CVE-2023-43540 — CVSS 8.4 (high) : Memory corruption while processing the IOCTL FM HCI WRITE request.CVE-2023-43541 — CVSS 8.4 (high) : Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.CVE-2023-28547 — CVSS 8.4 (high) : Memory corruption in SPS Application while requesting for public key in sorter TA.CVE-2023-33022 — CVSS 8.4 (high) : Memory corruption in HLOS while invoking IOCTL calls from user-space.CVE-2023-33023 — CVSS 8.4 (high) : Memory corruption while processing finish_sign command to pass a rsp buffer.CVE-2024-21481 — CVSS 8.4 (high) : Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.CVE-2024-21474 — CVSS 8.4 (high) : Memory corruption when size of buffer from previous call is used without validation or re-initialization.CVE-2024-21470 — CVSS 8.4 (high) : Memory corruption while allocating memory for graphics.CVE-2023-43531 — CVSS 8.4 (high) : Memory corruption while verifying the serialized header when the key pairs are generated.CVE-2023-43532 — CVSS 8.4 (high) : Memory corruption while reading ACPI config through the user mode app.CVE-2024-21461 — CVSS 8.4 (high) : Memory corruption while performing finish HMAC operation when context is freed by keymaster.CVE-2023-24852 — CVSS 8.4 (high) : Memory Corruption in Core due to secure memory access by user while loading modem image.CVE-2024-33065 — CVSS 8.4 (high) : Memory corruption while taking snapshot when an offset variable is set by camera driver.CVE-2023-33088 — CVSS 8.4 (high) : Memory corruption when processing cmd parameters while parsing vdev.CVE-2024-33056 — CVSS 8.4 (high) : Memory corruption when allocating and accessing an entry in an SMEM partition continuously.CVE-2024-33047 — CVSS 8.4 (high) : Memory corruption when the captureRead QDCM command is invoked from user-space.CVE-2024-33044 — CVSS 8.4 (high) : Memory corruption while Configuring the SMR/S2CR register in Bypass mode.CVE-2024-23360 — CVSS 8.4 (high) : Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.CVE-2023-33119 — CVSS 8.4 (high) : Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.CVE-2024-49838 — CVSS 8.2 (high) : Information disclosure while parsing the OCI IE with invalid length.CVE-2023-28585 — CVSS 8.2 (high) : Memory corruption while loading an ELF segment in TEE Kernel.CVE-2023-28545 — CVSS 8.2 (high) : Memory corruption in TZ Secure OS while loading an app ELF.CVE-2026-24088 — CVSS 8.2 (high) : Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.CVE-2024-38408 — CVSS 8.2 (high) : Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.CVE-2024-53011 — CVSS 7.9 (high) : Information disclosure may occur due to improper permission and access controls to Video Analytics engine.CVE-2024-45547 — CVSS 7.8 (high) : Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.CVE-2023-28546 — CVSS 7.8 (high) : Memory Corruption in SPS Application while exporting public key in sorter TA.CVE-2023-28550 — CVSS 7.8 (high) : Memory corruption in MPP performance while accessing DSM watermark using external memory address.CVE-2023-28587 — CVSS 7.8 (high) : Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.CVE-2023-33017 — CVSS 7.8 (high) : Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.CVE-2023-33115 — CVSS 7.8 (high) : Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.CVE-2023-43542 — CVSS 7.8 (high) : Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.CVE-2024-45548 — CVSS 7.8 (high) : Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.CVE-2024-45550 — CVSS 7.8 (high) : Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.CVE-2024-45557 — CVSS 7.8 (high) : Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.CVE-2024-45560 — CVSS 7.8 (high) : Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.CVE-2024-45561 — CVSS 7.8 (high) : Memory corruption while handling IOCTL call from user-space to set latency level.CVE-2024-45573 — CVSS 7.8 (high) : Memory corruption may occour while generating test pattern due to negative indexing of display ID.CVE-2024-49835 — CVSS 7.8 (high) : Memory corruption while reading secure file.CVE-2024-49840 — CVSS 7.8 (high) : Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.CVE-2024-49841 — CVSS 7.8 (high) : Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.CVE-2024-49842 — CVSS 7.8 (high) : Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.CVE-2024-49844 — CVSS 7.8 (high) : Memory corruption while triggering commands in the PlayReady Trusted application.CVE-2024-49845 — CVSS 7.8 (high) : Memory corruption during the FRS UDS generation process.CVE-2024-53010 — CVSS 7.8 (high) : Memory corruption may occur while attaching VM when the HLOS retains access to VM.CVE-2024-53033 — CVSS 7.8 (high) : Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.CVE-2024-53034 — CVSS 7.8 (high) : Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the…CVE-2025-21421 — CVSS 7.8 (high) : Memory corruption while processing escape code in API.CVE-2025-21423 — CVSS 7.8 (high) : Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.CVE-2025-21432 — CVSS 7.8 (high) : Memory corruption while retrieving the CBOR data from TA.CVE-2025-21438 — CVSS 7.8 (high) : Memory corruption while IOCTL call is invoked from user-space to read board data.CVE-2025-21440 — CVSS 7.8 (high) : Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.CVE-2025-21441 — CVSS 7.8 (high) : Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.CVE-2025-21447 — CVSS 7.8 (high) : Memory corruption may occur while processing device IO control call for session control.CVE-2025-21462 — CVSS 7.8 (high) : Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.CVE-2025-21466 — CVSS 7.8 (high) : Memory corruption while processing a private escape command in an event trigger.CVE-2025-21469 — CVSS 7.8 (high) : Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.CVE-2025-21470 — CVSS 7.8 (high) : Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.CVE-2025-21475 — CVSS 7.8 (high) : Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.CVE-2025-21481 — CVSS 7.8 (high) : Memory corruption while performing private key encryption in trusted application.CVE-2025-27031 — CVSS 7.8 (high) : memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.CVE-2025-27032 — CVSS 7.8 (high) : memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.CVE-2025-27044 — CVSS 7.8 (high) : Memory corruption while executing timestamp video decode command with large input values.CVE-2025-27046 — CVSS 7.8 (high) : Memory corruption while processing multiple simultaneous escape calls.CVE-2025-27047 — CVSS 7.8 (high) : Memory corruption while processing the TESTPATTERNCONFIG escape path.CVE-2025-27048 — CVSS 7.8 (high) : Memory corruption while processing camera platform driver IOCTL calls.CVE-2025-27050 — CVSS 7.8 (high) : Memory corruption while processing event close when client process terminates abruptly.CVE-2025-27051 — CVSS 7.8 (high) : Memory corruption while processing command message in WLAN Host.CVE-2025-27053 — CVSS 7.8 (high) : Memory corruption during PlayReady APP usecase while processing TA commands.CVE-2025-27054 — CVSS 7.8 (high) : Memory corruption while processing a malformed license file during reboot.CVE-2025-27055 — CVSS 7.8 (high) : Memory corruption during the image encoding process.CVE-2025-27058 — CVSS 7.8 (high) : Memory corruption while processing packet data with exceedingly large packet.CVE-2025-27067 — CVSS 7.8 (high) : Memory corruption while processing DDI call with invalid buffer.CVE-2025-27068 — CVSS 7.8 (high) : Memory corruption while processing an IOCTL command with an arbitrary address.CVE-2025-27069 — CVSS 7.8 (high) : Memory corruption while processing DDI command calls.CVE-2025-27070 — CVSS 7.8 (high) : Memory corruption while performing encryption and decryption commands.CVE-2025-27075 — CVSS 7.8 (high) : Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.CVE-2025-27076 — CVSS 7.8 (high) : Memory corruption while processing simultaneous requests via escape path.CVE-2025-47316 — CVSS 7.8 (high) : Memory corruption due to double free when multiple threads race to set the timestamp store.CVE-2025-47323 — CVSS 7.8 (high) : Memory corruption while routing GPR packets between user and root when handling large data packet.CVE-2025-47327 — CVSS 7.8 (high) : Memory corruption while encoding the image data.CVE-2025-47338 — CVSS 7.8 (high) : Memory corruption while processing escape commands from userspace.CVE-2025-47339 — CVSS 7.8 (high) : Memory corruption while deinitializing a HDCP session.CVE-2025-47340 — CVSS 7.8 (high) : Memory corruption while processing IOCTL call to get the mapping.CVE-2025-47341 — CVSS 7.8 (high) : memory corruption while processing an image encoding completion event.CVE-2025-47343 — CVSS 7.8 (high) : Memory corruption while processing a video session to set video parameters.CVE-2025-47346 — CVSS 7.8 (high) : Memory corruption while processing a secure logging command in the trusted application.CVE-2025-47348 — CVSS 7.8 (high) : Memory corruption while processing identity credential operations in the trusted application.CVE-2025-47349 — CVSS 7.8 (high) : Memory corruption while processing an escape call.CVE-2025-47350 — CVSS 7.8 (high) : Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.CVE-2025-47355 — CVSS 7.8 (high) : Memory corruption while invoking remote procedure IOCTL calls.CVE-2025-47356 — CVSS 7.8 (high) : Memory Corruption when multiple threads concurrently access and modify shared resources.CVE-2025-47358 — CVSS 7.8 (high) : Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.CVE-2025-47359 — CVSS 7.8 (high) : Memory Corruption when multiple threads simultaneously access a memory free API.CVE-2025-47367 — CVSS 7.8 (high) : Memory corruption while accessing a buffer during IOCTL processing.CVE-2025-47368 — CVSS 7.8 (high) : Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.CVE-2025-47373 — CVSS 7.8 (high) : Memory Corruption when accessing buffers with invalid length during TA invocation.CVE-2025-47387 — CVSS 7.8 (high) : Memory Corruption when processing IOCTLs for JPEG data without verification.CVE-2025-47389 — CVSS 7.8 (high) : Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.CVE-2025-47390 — CVSS 7.8 (high) : Memory corruption while preprocessing IOCTL request in JPEG driver.CVE-2025-47405 — CVSS 7.8 (high) : Memory corruption when processing camera sensor input/output control codes with invalid output buffers.CVE-2025-47407 — CVSS 7.8 (high) : Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.CVE-2025-47408 — CVSS 7.8 (high) : Memory corruption when another driver calls an IOCTL with invalid input/output buffer.CVE-2025-59600 — CVSS 7.8 (high) : Memory Corruption when adding user-supplied data without checking available buffer space.CVE-2025-59603 — CVSS 7.8 (high) : Memory Corruption when processing invalid user address with nonstandard buffer address.CVE-2025-59604 — CVSS 7.8 (high) : Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.CVE-2026-21371 — CVSS 7.8 (high) : Memory Corruption when retrieving output buffer with insufficient size validation.CVE-2026-21373 — CVSS 7.8 (high) : Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.CVE-2026-21374 — CVSS 7.8 (high) : Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.CVE-2026-21375 — CVSS 7.8 (high) : Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.CVE-2026-21376 — CVSS 7.8 (high) : Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.CVE-2026-21378 — CVSS 7.8 (high) : Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.CVE-2026-21379 — CVSS 7.8 (high) : Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.CVE-2026-21380 — CVSS 7.8 (high) : Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.CVE-2026-21382 — CVSS 7.8 (high) : Memory Corruption when handling power management requests with improperly sized input/output buffers.CVE-2026-21385 — CVSS 7.8 (high) — actively exploited : Memory corruption while using alignments for memory allocation.CVE-2026-25258 — CVSS 7.8 (high) : Memory corruption while processing IOCTL calls for escape operations.CVE-2026-25259 — CVSS 7.8 (high) : Memory corruption while processing multiple IOCTL command for escape operations.CVE-2026-25260 — CVSS 7.8 (high) : Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.CVE-2026-25271 — CVSS 7.8 (high) : Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.CVE-2024-21465 — CVSS 7.8 (high) : Memory corruption while processing key blob passed by the user.CVE-2024-21476 — CVSS 7.8 (high) : Memory corruption when the channel ID passed by user is not validated and further used.CVE-2024-23355 — CVSS 7.8 (high) : Memory corruption when keymaster operation imports a shared key.CVE-2024-23356 — CVSS 7.8 (high) : Memory corruption during session sign renewal request calls in HLOS.CVE-2024-23369 — CVSS 7.8 (high) : Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.CVE-2024-38406 — CVSS 7.8 (high) : Memory corruption while handling IOCTL calls in JPEG Encoder driver.CVE-2024-38407 — CVSS 7.8 (high) : Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.CVE-2024-38409 — CVSS 7.8 (high) : Memory corruption while station LL statistic handling.CVE-2024-38410 — CVSS 7.8 (high) : Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.CVE-2024-43049 — CVSS 7.8 (high) : Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.CVE-2024-43050 — CVSS 7.8 (high) : Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.CVE-2024-43052 — CVSS 7.8 (high) : Memory corruption while processing API calls to NPU with invalid input.CVE-2024-43053 — CVSS 7.8 (high) : Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.CVE-2024-45541 — CVSS 7.8 (high) : Memory corruption when IOCTL call is invoked from user-space to read board data.CVE-2024-45542 — CVSS 7.8 (high) : Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.CVE-2024-45546 — CVSS 7.8 (high) : Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.CVE-2024-45549 — CVSS 7.7 (high) : Information disclosure while creating MQ channels.CVE-2026-21381 — CVSS 7.6 (high) : Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network…CVE-2026-25292 — CVSS 7.6 (high) : Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.CVE-2026-21367 — CVSS 7.6 (high) : Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.CVE-2023-43539 — CVSS 7.5 (high) : Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.CVE-2023-43536 — CVSS 7.5 (high) : Transient DOS while parse fils IE with length equal to 1.CVE-2023-43533 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.CVE-2023-43523 — CVSS 7.5 (high) : Transient DOS while processing 11AZ RTT management action frame received through OTA.CVE-2024-21477 — CVSS 7.5 (high) : Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.CVE-2023-43522 — CVSS 7.5 (high) : Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.CVE-2023-33105 — CVSS 7.5 (high) : Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence…CVE-2024-23363 — CVSS 7.5 (high) : Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.CVE-2024-23364 — CVSS 7.5 (high) : Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon…CVE-2024-33013 — CVSS 7.5 (high) : Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.CVE-2023-33098 — CVSS 7.5 (high) : Transient DOS while parsing WPA IES, when it is passed with length more than expected size.CVE-2023-33097 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware while processing a FTMR frame.CVE-2024-33051 — CVSS 7.5 (high) : Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.CVE-2023-33089 — CVSS 7.5 (high) : Transient DOS when processing a NULL buffer while parsing WLAN vdev.CVE-2024-33058 — CVSS 7.5 (high) : Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.CVE-2023-33081 — CVSS 7.5 (high) : Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.CVE-2024-38403 — CVSS 7.5 (high) : Transient DOS while parsing BTM ML IE when per STA profile is not included.CVE-2023-33061 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.CVE-2025-27057 — CVSS 7.5 (high) : Transient DOS while handling beacon frames with invalid IE header length.CVE-2025-27065 — CVSS 7.5 (high) : Transient DOS while processing a frame with malformed shared-key descriptor.CVE-2025-27066 — CVSS 7.5 (high) : Transient DOS while processing an ANQP message.CVE-2023-33056 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.CVE-2025-27073 — CVSS 7.5 (high) : Transient DOS while creating NDP instance.CVE-2023-33048 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware while parsing t2lm buffers.CVE-2025-21446 — CVSS 7.5 (high) : Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.CVE-2025-21448 — CVSS 7.5 (high) : Transient DOS may occur while parsing SSID in action frames.CVE-2025-21449 — CVSS 7.5 (high) : Transient DOS may occur while processing malformed length field in SSID IEs.CVE-2025-21454 — CVSS 7.5 (high) : Transient DOS while processing received beacon frame.CVE-2023-33041 — CVSS 7.5 (high) : Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.CVE-2025-21463 — CVSS 7.5 (high) : Transient DOS while processing the EHT operation IE in the received beacon frame.CVE-2023-33047 — CVSS 7.5 (high) : Transient DOS in WLAN Firmware while parsing no-inherit IES.CVE-2026-25288 — CVSS 7.4 (high) : Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.CVE-2024-21469 — CVSS 7.3 (high) : Memory corruption when an invoke call and a TEE call are bound for the same trusted application.CVE-2026-24092 — CVSS 7.2 (high) : Memory Corruption when processing fastboot commands to set display mode.CVE-2026-24091 — CVSS 7.2 (high) : Memory corruption while processing fastboot commands with improperly formatted input.CVE-2026-24087 — CVSS 7.2 (high) : Memory corruption while processing fastboot OEM commands.CVE-2026-24085 — CVSS 7.2 (high) : Memory Corruption when processing display command line information due to improper initialization of a variable.CVE-2026-24089 — CVSS 7.2 (high) : Memory corruption while processing fastboot commands with invalid input.CVE-2023-28556 — CVSS 7.1 (high) : Cryptographic issue in HLOS during key management.CVE-2025-21482 — CVSS 7.1 (high) : Cryptographic issue while performing RSA PKCS padding decoding.CVE-2024-43065 — CVSS 7.1 (high) : Cryptographic issues while generating an asymmetric key pair for RKP use cases.CVE-2025-21422 — CVSS 7.1 (high) : Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.CVE-2025-47366 — CVSS 7.1 (high) : Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.CVE-2024-23362 — CVSS 7.1 (high) : Cryptographic issue while parsing RSA keys in COBR format.CVE-2026-24090 — CVSS 7.1 (high) : Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.CVE-2024-21462 — CVSS 7.1 (high) : Transient DOS while loading the TA ELF file.CVE-2024-33016 — CVSS 6.8 (medium) : memory corruption when an invalid firehose patch command is invoked.CVE-2026-24076 — CVSS 6.7 (medium) : Memory Corruption when processing registry values with incorrect types using a direct query method.