Home/Product/qualcomm msm8996 firmware
Product

qualcomm msm8996 firmware

72 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-11207
all versions
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Com
7.8HIGH
CVE-2020-11196
all versions
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon A
9.8CRITICAL
CVE-2020-11193
all versions
u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Aut
9.8CRITICAL
CVE-2020-11123
all versions
u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at get
5.5MEDIUM
CVE-2020-3644
all versions
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in
5.5MEDIUM
CVE-2020-3643
all versions
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Com
5.5MEDIUM
CVE-2020-3622
all versions
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated fo
7.8HIGH
CVE-2020-3621
all versions
u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size res
5.5MEDIUM
CVE-2020-3620
all versions
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport ca
5.5MEDIUM
CVE-2019-14115
all versions
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which c
5.5MEDIUM
CVE-2019-14074
all versions
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon C
7.8HIGH
CVE-2019-13999
all versions
u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information
7.8HIGH
CVE-2019-13998
all versions
u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into mem
7.8HIGH
CVE-2019-13995
all versions
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to mem
7.8HIGH
CVE-2019-13994
all versions
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than
7.8HIGH
CVE-2019-10615
all versions
u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of
7.8HIGH
CVE-2019-10527
all versions
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address
7.8HIGH
CVE-2020-3688
all versions
Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto
9.8CRITICAL
CVE-2019-14101
all versions
Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than
7.1HIGH
CVE-2019-14093
all versions
Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snap
7.8HIGH
CVE-2019-14037
all versions
Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdra
7.8HIGH
CVE-2020-3665
all versions
A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firmware being
7.8HIGH
CVE-2020-3663
all versions
Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto,
9.8CRITICAL
CVE-2020-3662
all versions
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2020-3661
all versions
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due to lack o
9.8CRITICAL
CVE-2020-3660
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2020-3658
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.1CRITICAL
CVE-2019-14094
all versions
Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdra
7.8HIGH
CVE-2019-14047
all versions
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA H
7.8HIGH
CVE-2019-10597
all versions
kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2020-3630
all versions
Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Compute, Snap
7.8HIGH
CVE-2019-14067
all versions
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channe
5.5MEDIUM
CVE-2019-14110
all versions
Buffer overflow can occur in function wlan firmware while copying association frame content if frame length is more than the maxim
9.8CRITICAL
CVE-2019-14007
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.5MEDIUM
CVE-2019-10574
all versions
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute,
7.1HIGH
CVE-2019-10483
all versions
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snap
5.5MEDIUM
CVE-2019-2311
all versions
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapdragon Auto
9.8CRITICAL
CVE-2019-2300
all versions
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in Snapdragon
9.8CRITICAL
CVE-2019-14095
all versions
Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specification in S
9.8CRITICAL
CVE-2019-14071
all versions
Compromised reset handler may bypass access control due to AC config is being reset if debug path is enabled to collect secure or
7.8HIGH
CVE-2019-14061
all versions
Null-pointer dereference can occur while accessing the segment element info when it is not allocated and assigned in Snapdragon Au
7.5HIGH
CVE-2019-14031
all versions
Buffer overflow can occur while parsing RSN IE containing list of PMK ID`s which are more than the buffer size in Snapdragon Auto,
9.8CRITICAL
CVE-2019-14015
all versions
A stack-based buffer overflow exists in the initialization of the identification stage due to lack of check on the number of templ
7.8HIGH
CVE-2019-14000
all versions
Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption
7.8HIGH
CVE-2019-10591
all versions
Null pointer dereference can happen when parsing udta atom which is non-standard and having invalid depth in Snapdragon Auto, Snap
7.5HIGH
CVE-2019-14057
all versions
Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Aut
9.1CRITICAL
CVE-2019-10590
all versions
Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, S
9.8CRITICAL
CVE-2019-14017
all versions
Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdrag
9.8CRITICAL
CVE-2019-14016
all versions
Integer overflow occurs while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
9.8CRITICAL
CVE-2019-14013
all versions
While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read in
9.8CRITICAL
CVE-2019-14006
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2019-14005
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdr
9.8CRITICAL
CVE-2019-14004
all versions
Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2019-14003
all versions
Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment information in Sna
7.5HIGH
CVE-2019-10611
all versions
Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon
9.8CRITICAL
CVE-2019-10579
all versions
Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon C
9.1CRITICAL
CVE-2019-10578
all versions
Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5HIGH
CVE-2019-10561
all versions
Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and leads to deni
5.5MEDIUM
CVE-2019-10532
all versions
Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Sna
9.8CRITICAL
CVE-2019-10607
all versions
Out of bounds memcpy can occur by providing the embedded NULL character string and length greater than the actual string length in
7.8HIGH
CVE-2019-10513
all versions
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snap
5.5MEDIUM
CVE-2019-10482
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.9MEDIUM
CVE-2019-2321
all versions
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Au
7.8HIGH
CVE-2019-2288
all versions
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Au
7.8HIGH
CVE-2019-10559
all versions
Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corrup
9.8CRITICAL
CVE-2019-2318
all versions
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Con
5.5MEDIUM
CVE-2019-2315
all versions
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure enviro
7.8HIGH
CVE-2019-10490
all versions
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto
5.5MEDIUM
CVE-2018-13916
all versions
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data
7.8HIGH
CVE-2014-10050
all versions
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MSM8996, MSM8939, MSM8976, MSM8917, SDM
9.8CRITICAL
CVE-2017-18132
all versions
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, MDM899
9.8CRITICAL
CVE-2017-18129
all versions
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin