CVE-2025-27036Medium· 6.1▾ SunlitInformation disclosure when Video engine escape input data is less than expected minimum size.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.08%
Information disclosure when Video engine escape input data is less than expected minimum size.
fastconnect_6700_firmwarefastconnect_6900_firmwarefastconnect_7800_firmwareqcm5430_firmwareqcm6490_firmwareqcs5430_firmwareqcs6490_firmwarevideo_collaboration_vc3_platform_firmwaresc8380xp_firmwaresnapdragon_7c+_gen_3_compute_firmwaresnapdragon_8cx_gen_3_compute_platform_(sc8280xp-ab)_firmwaresnapdragon_8cx_gen_3_compute_platform_(sc8280xp-bb)_firmwarewcd9370_firmwarewcd9375_firmwarewcd9380_firmwarewcd9385_firmwarewsa8830_firmwarewsa8835_firmwarewsa8840_firmwarewsa8845_firmwarewsa8845h_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-27033Medium· 6.1Information disclosure while running video usecase having rogue firmware.
CVE-2025-27030Medium· 6.1information disclosure while invoking calibration data from user space to update firmware size.
CVE-2025-21488High· 8.2Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-21487High· 8.2Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484High· 8.2Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482High· 7.1Cryptographic issue while performing RSA PKCS padding decoding.