Home/Product/qualcomm qcx315 firmware
Product

qualcomm qcx315 firmware

132 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-21646
all versions
Transient DOS in Modem while processing invalid System Information Block 1.
7.5HIGH
CVE-2023-22666
all versions
Memory Corruption in Audio while playing amrwbplus clips with modified content.
8.4HIGH
CVE-2023-21651
all versions
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
9.3CRITICAL
CVE-2023-21626
all versions
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
7.1HIGH
CVE-2022-40510
all versions
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
9.8CRITICAL
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4HIGH
CVE-2022-40530
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
8.4HIGH
CVE-2022-33272
all versions
Transient DOS in modem due to reachable assertion.
7.5HIGH
CVE-2022-33256
all versions
Memory corruption due to improper validation of array index in Multi-mode call processor.
9.8CRITICAL
CVE-2022-33254
all versions
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
7.5HIGH
CVE-2022-33250
all versions
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
7.5HIGH
CVE-2022-33213
all versions
Memory corruption in modem due to buffer overflow while processing a PPP packet
7.5HIGH
CVE-2022-25709
all versions
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
8.4HIGH
CVE-2022-25705
all versions
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
7.8HIGH
CVE-2022-25694
all versions
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
8.4HIGH
CVE-2022-22075
all versions
Information Disclosure in Graphics during GPU context switch.
6.2MEDIUM
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5HIGH
CVE-2022-33277
all versions
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
8.4HIGH
CVE-2022-33248
all versions
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
7.8HIGH
CVE-2022-33233
all versions
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
7.8HIGH
CVE-2022-40520
all versions
Memory corruption due to stack-based buffer overflow in Core
8.4HIGH
CVE-2022-40519
all versions
Information disclosure due to buffer overread in Core
6.8MEDIUM
CVE-2022-40518
all versions
Information disclosure due to buffer overread in Core
6.8MEDIUM
CVE-2022-40517
all versions
Memory corruption in core due to stack-based buffer overflow
8.4HIGH
CVE-2022-40516
all versions
Memory corruption in Core due to stack-based buffer overflow.
8.4HIGH
CVE-2022-33286
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
7.5HIGH
CVE-2022-33285
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
7.5HIGH
CVE-2022-33253
all versions
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
7.5HIGH
CVE-2022-33252
all versions
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
8.2HIGH
CVE-2022-25725
all versions
Denial of service in MODEM due to improper pointer handling
6.2MEDIUM
CVE-2022-33238
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
7.5HIGH
CVE-2022-33235
all versions
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto
8.2HIGH
CVE-2022-25702
all versions
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Comp
7.5HIGH
CVE-2022-25695
all versions
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto,
8.4HIGH
CVE-2022-25692
all versions
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2022-25685
all versions
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapd
7.5HIGH
CVE-2022-25682
all versions
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Sn
8.4HIGH
CVE-2022-25675
all versions
Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute,
5.5MEDIUM
CVE-2022-33239
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
7.5HIGH
CVE-2022-33237
all versions
Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Sna
7.5HIGH
CVE-2022-25724
all versions
Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Sna
8.4HIGH
CVE-2022-25749
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
7.5HIGH
CVE-2022-25748
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
9.8CRITICAL
CVE-2022-25736
all versions
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Comput
7.5HIGH
CVE-2022-25720
all versions
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdrag
9.8CRITICAL
CVE-2021-35104
all versions
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compu
9.8CRITICAL
CVE-2021-35071
all versions
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of
5.5MEDIUM
CVE-2021-30350
all versions
Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Sn
8.4HIGH
CVE-2021-30349
all versions
Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto
8.2HIGH
CVE-2021-30347
all versions
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been re
9.1CRITICAL
CVE-2021-30344
all versions
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Comp
7.5HIGH
CVE-2021-30343
all versions
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received
9.1CRITICAL
CVE-2021-30341
all versions
Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapd
9.8CRITICAL
CVE-2021-30340
all versions
Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute
7.5HIGH
CVE-2021-30334
all versions
Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-30281
all versions
Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device con
8.4HIGH
CVE-2021-35117
all versions
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Co
8.2HIGH
CVE-2021-35105
all versions
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, S
8.4HIGH
CVE-2021-35088
all versions
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Sn
8.2HIGH
CVE-2021-30333
all versions
Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Sna
7.8HIGH
CVE-2021-30332
all versions
Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
7.5HIGH
CVE-2021-30331
all versions
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdrag
5.5MEDIUM
CVE-2021-30329
all versions
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
7.5HIGH
CVE-2021-30328
all versions
Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute,
7.5HIGH
CVE-2021-1942
all versions
Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, S
9.3CRITICAL
CVE-2021-35069
all versions
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2021-30326
all versions
Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup
7.5HIGH
CVE-2021-30322
all versions
Possible out of bounds write due to improper validation of number of GPIOs configured in an internal parameters array in Snapdrago
7.8HIGH
CVE-2021-30318
all versions
Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute,
8.4HIGH
CVE-2021-30317
all versions
Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdrago
9.3CRITICAL
CVE-2021-30353
all versions
Improper validation of function pointer type with actual function signature can lead to assertion in Snapdragon Auto, Snapdragon C
7.5HIGH
CVE-2021-30319
all versions
Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto,
7.8HIGH
CVE-2021-30311
all versions
Possible heap overflow due to lack of index validation before allocating and writing to heap buffer in Snapdragon Auto, Snapdragon
7.8HIGH
CVE-2021-30308
all versions
Possible buffer overflow while printing the HARQ memory partition detail due to improper validation of buffer size in Snapdragon A
7.8HIGH
CVE-2021-30307
all versions
Possible denial of service due to improper validation of DNS response when DNS client requests with PTR, NAPTR or SRV query type i
7.5HIGH
CVE-2021-30301
all versions
Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon Industrial
7.5HIGH
CVE-2021-30300
all versions
Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and assigning a garbage value to choice w
7.5HIGH
CVE-2021-30287
all versions
Possible assertion due to improper validation of symbols configured for PDCCH monitoring in Snapdragon Auto, Snapdragon Compute, S
7.5HIGH
CVE-2021-30285
all versions
Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Sn
9.3CRITICAL
CVE-2021-30351
all versions
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapd
9.8CRITICAL
CVE-2021-30348
all versions
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapd
6.5MEDIUM
CVE-2021-30337
all versions
Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdrago
8.4HIGH
CVE-2021-30335
all versions
Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Sn
8.4HIGH
CVE-2021-30303
all versions
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon
7.8HIGH
CVE-2021-30293
all versions
Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
7.5HIGH
CVE-2021-30282
all versions
Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto,
8.4HIGH
CVE-2021-30279
all versions
Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapdragon Comp
7.8HIGH
CVE-2021-30278
all versions
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon
7.1HIGH
CVE-2021-30276
all versions
Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapd
9.3CRITICAL
CVE-2021-30275
all versions
Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Au
9.3CRITICAL
CVE-2021-30274
all versions
Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Aut
8.4HIGH
CVE-2021-30272
all versions
Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon
7.3HIGH
CVE-2021-30271
all versions
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto,
7.3HIGH
CVE-2021-30270
all versions
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Sn
7.3HIGH
CVE-2021-30269
all versions
Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute,
7.3HIGH
CVE-2021-30268
all versions
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Sna
7.8HIGH
CVE-2021-30267
all versions
Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Snapdragon C
7.8HIGH
CVE-2021-1894
all versions
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon
7.1HIGH
CVE-2020-11263
all versions
An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdrago
7.3HIGH
CVE-2021-30259
all versions
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdrag
7.8HIGH
CVE-2021-30255
all versions
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapd
7.8HIGH
CVE-2021-30254
all versions
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdra
7.8HIGH
CVE-2021-1982
all versions
Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Co
7.5HIGH
CVE-2021-1981
all versions
Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snapdragon Aut
7.5HIGH
CVE-2021-1979
all versions
Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
7.8HIGH
CVE-2021-1975
all versions
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Comput
9.8CRITICAL
CVE-2021-1973
all versions
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
7.8HIGH
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0CRITICAL
CVE-2021-1912
all versions
Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snap
8.4HIGH
CVE-2021-1903
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
5.3MEDIUM
CVE-2021-30316
all versions
Possible out of bound memory access due to improper boundary check while creating HSYNC fence in Snapdragon Auto, Snapdragon Conne
8.4HIGH
CVE-2021-30312
all versions
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2021-30302
all versions
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Comput
7.5HIGH
CVE-2021-1980
all versions
Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Sna
7.5HIGH
CVE-2021-1959
all versions
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
7.8HIGH
CVE-2021-1913
all versions
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-30261
all versions
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from
8.4HIGH
CVE-2021-1976
all versions
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2021-30295
all versions
Possible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon A
8.4HIGH
CVE-2021-1971
all versions
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
7.5HIGH
CVE-2021-1960
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
6.5MEDIUM
CVE-2021-1956
all versions
Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Sn
6.5MEDIUM
CVE-2021-1952
all versions
Possible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.8HIGH
CVE-2021-1948
all versions
Possible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snap
7.5HIGH
CVE-2021-1935
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
7.1HIGH
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3HIGH
CVE-2021-1972
all versions
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2021-1920
all versions
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon C
9.8CRITICAL
CVE-2021-1919
all versions
Integer underflow can occur when the RTCP length is lesser than the actual blocks present in Snapdragon Auto, Snapdragon Comp
9.8CRITICAL
CVE-2021-1916
all versions
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto,
9.8CRITICAL
CVE-2021-1914
all versions
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Comput
7.5HIGH
CVE-2021-1904
all versions
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Sna
6.2MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin