Product
qualcomm sd 8cx firmware
339 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-27032
CVE-2025-21482
CVE-2025-21465
CVE-2025-21464
CVE-2025-21454
CVE-2025-21449
CVE-2025-21422
CVE-2024-53009
CVE-2024-53010
CVE-2024-49842
CVE-2024-49841
CVE-2024-43046
CVE-2024-33058
CVE-2024-43056
CVE-2024-38420
CVE-2024-33056
CVE-2024-33044
CVE-2024-33051
CVE-2024-33016
CVE-2024-23362
CVE-2024-21481
CVE-2024-21469
CVE-2024-21465
CVE-2024-21462
CVE-2023-43542
CVE-2023-43538
CVE-2023-43530
CVE-2023-33119
CVE-2023-33115
CVE-2023-33066
CVE-2023-28578
CVE-2023-43536
CVE-2023-43533
CVE-2023-33076
CVE-2023-33072
CVE-2023-43511
CVE-2023-33109
CVE-2023-33062
CVE-2023-33036
CVE-2023-33033
CVE-2023-33030
CVE-2023-33088
CVE-2023-33080
CVE-2023-28586
CVE-2023-28585
CVE-2023-28550
CVE-2023-28569
CVE-2023-28566
CVE-2023-28563
CVE-2023-28545
CVE-2023-24852
CVE-2023-33027
CVE-2023-24847
CVE-2023-21673
CVE-2023-28567
CVE-2023-28565
CVE-2023-28564
CVE-2023-28560
CVE-2023-28559
CVE-2023-28558
CVE-2023-28557
CVE-2023-28544
CVE-2023-28538
CVE-2023-21664
CVE-2023-21662
CVE-2022-33275
CVE-2023-21651
CVE-2022-40510
CVE-2023-21659
CVE-2023-21628
CVE-2022-40529
CVE-2022-40523
CVE-2022-40507
CVE-2022-33307
CVE-2022-22076
CVE-2022-33273
CVE-2022-40532
CVE-2022-33288
CVE-2022-33269
CVE-2022-33231
CVE-2022-40531
CVE-2022-40530
CVE-2022-33257
CVE-2022-33242
CVE-2022-25655
CVE-2022-40514
CVE-2022-40512
CVE-2022-33277
CVE-2022-33271
CVE-2022-33232
CVE-2022-40520
CVE-2022-40519
CVE-2022-40518
CVE-2022-40517
CVE-2022-40516
CVE-2022-33286
CVE-2022-33285
CVE-2022-25746
CVE-2022-33238
CVE-2022-33235
CVE-2022-25681
CVE-2022-33239
CVE-2022-33237
CVE-2022-25749
CVE-2022-25748
CVE-2022-25736
CVE-2022-25665
CVE-2022-25661
CVE-2022-25660
CVE-2022-25690
CVE-2022-22094
CVE-2022-22093
CVE-2022-22070
CVE-2022-22062
CVE-2021-35122
CVE-2021-35097
CVE-2021-35101
CVE-2021-35090
CVE-2021-35083
CVE-2021-35078
CVE-2021-30348
CVE-2021-30303
CVE-2021-30289
CVE-2021-30282
CVE-2021-30278
CVE-2021-30275
CVE-2021-30274
CVE-2021-30273
CVE-2021-30272
CVE-2021-30271
CVE-2021-30270
CVE-2021-30269
CVE-2021-30268
CVE-2021-30267
CVE-2021-1894
CVE-2021-30321
CVE-2021-30263
CVE-2021-30259
CVE-2021-30255
CVE-2021-1979
CVE-2021-1975
CVE-2021-1973
CVE-2021-1924
CVE-2021-1921
CVE-2021-1912
CVE-2021-1903
CVE-2021-30302
CVE-2021-30288
CVE-2021-1980
CVE-2021-1969
CVE-2021-1968
CVE-2021-1967
CVE-2021-1966
CVE-2021-1959
CVE-2021-1932
CVE-2021-1913
CVE-2021-30261
CVE-2021-30260
CVE-2021-1974
CVE-2021-1971
CVE-2021-1963
CVE-2021-1961
CVE-2021-1960
CVE-2021-1956
CVE-2021-1952
CVE-2021-1948
CVE-2021-1946
CVE-2021-1941
CVE-2021-1935
CVE-2021-1933
CVE-2021-1909
CVE-2021-1972
CVE-2021-1923
CVE-2021-1920
CVE-2021-1919
CVE-2021-1916
CVE-2021-1914
CVE-2021-1904
CVE-2020-11301
CVE-2020-11264
CVE-2021-1970
CVE-2021-1964
CVE-2021-1955
CVE-2021-1953
CVE-2021-1945
CVE-2021-1940
CVE-2021-1938
CVE-2021-1931
CVE-2021-1896
CVE-2021-1890
CVE-2021-1889
CVE-2021-1888
CVE-2021-1886
CVE-2021-1937
CVE-2021-1900
CVE-2020-11306
CVE-2020-11304
CVE-2020-11298
CVE-2020-11292
CVE-2020-11291
CVE-2020-11267
CVE-2020-11176
CVE-2020-11262
CVE-2020-11261
CVE-2020-11250
CVE-2020-11241
CVE-2020-11240
CVE-2020-11239
CVE-2020-11238
CVE-2020-11235
CVE-2020-11182
CVE-2020-11178
CVE-2020-11165
CVE-2020-11160
CVE-2020-11159
CVE-2020-11134
CVE-2020-11126
CVE-2021-1927
CVE-2021-1925
CVE-2021-1915
CVE-2021-1906
CVE-2021-1905
CVE-2021-1895
CVE-2021-1891
CVE-2020-11293
CVE-2020-11289
CVE-2020-11288
CVE-2020-11285
CVE-2020-11284
CVE-2020-11279
CVE-2020-11274
CVE-2021-1892
CVE-2020-11255
CVE-2020-11252
CVE-2020-11251
CVE-2020-11245
CVE-2020-11243
CVE-2020-11234
CVE-2020-11191
CVE-2020-11309
CVE-2020-11308
CVE-2020-11230
CVE-2020-11228
CVE-2020-11227
CVE-2020-11226
CVE-2020-11222
CVE-2020-11221
CVE-2020-11220
CVE-2020-11218
CVE-2020-11199
CVE-2020-11192
CVE-2020-11190
CVE-2020-11189
CVE-2020-11188
CVE-2020-11171
CVE-2020-11166
CVE-2020-3664
CVE-2020-11297
CVE-2020-11296
CVE-2020-11281
CVE-2020-11280
CVE-2020-11278
CVE-2020-11276
CVE-2020-11275
CVE-2020-11272
CVE-2020-11271
CVE-2020-11270
CVE-2020-11269
CVE-2020-11253
CVE-2020-11204
CVE-2020-11198
CVE-2020-11195
CVE-2020-11177
CVE-2020-11170
CVE-2020-11163
CVE-2020-11119
CVE-2019-2285
CVE-2019-2275
CVE-2019-2258
CVE-2019-2249
CVE-2019-2246
CVE-2019-10496
CVE-2019-10495
CVE-2019-2294
CVE-2019-2252
CVE-2019-10540
CVE-2019-10539
CVE-2019-2346
CVE-2019-2343
CVE-2019-2281
CVE-2019-2273
CVE-2019-2254
CVE-2019-2241
CVE-2019-2240
CVE-2019-2239
CVE-2019-2238
CVE-2019-2237
CVE-2019-2236
CVE-2019-2235
CVE-2019-2261
CVE-2018-13927
CVE-2018-13924
CVE-2018-13896
CVE-2019-2259
CVE-2019-2256
CVE-2019-2255
CVE-2018-5913
CVE-2018-13911
CVE-2018-13909
CVE-2018-13908
CVE-2018-13907
CVE-2018-13906
CVE-2018-13902
CVE-2018-13898
CVE-2017-8252
CVE-2019-2250
CVE-2018-12013
CVE-2018-12012
CVE-2018-12004
CVE-2018-11976
CVE-2018-11968
CVE-2018-11928
CVE-2018-11971
CVE-2018-11970
CVE-2018-5839
CVE-2018-13904
CVE-2018-11948
CVE-2018-11945
CVE-2018-11938
CVE-2018-11935
CVE-2018-11932
CVE-2018-11931
CVE-2018-11864
CVE-2018-11845
CVE-2018-11820
CVE-2018-11289
CVE-2018-11888
CVE-2018-11855
CVE-2018-11847
all versions
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
all versions
Information disclosure while processing the hash segment in an MBN file.
all versions
Information disclosure while reading data from an image using specified offset and size parameters.
all versions
Transient DOS while processing received beacon frame.
all versions
Transient DOS may occur while processing malformed length field in SSID IEs.
all versions
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
all versions
Memory corruption while operating the mailbox in Automotive.
all versions
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
all versions
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
all versions
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
all versions
There may be information disclosure during memory re-allocation in TZ Secure OS.
all versions
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
all versions
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
all versions
Memory corruption while configuring a Hypervisor based input virtual device.
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
all versions
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
all versions
memory corruption when an invalid firehose patch command is invoked.
all versions
Cryptographic issue while parsing RSA keys in COBR format.
all versions
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
all versions
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
all versions
Memory corruption while processing key blob passed by the user.
all versions
Transient DOS while loading the TA ELF file.
all versions
Memory corruption while copying a keyblob
s material when the key materials size is not accurately checked.all versions
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
all versions
Memory corruption in HLOS while checking for the storage type.
all versions
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
all versions
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
all versions
Memory corruption in Audio while processing RT proxy port register driver.
all versions
Memory corruption in Core Services while executing the command for removing a single event listener.
all versions
Transient DOS while parse fils IE with length equal to 1.
all versions
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
all versions
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
all versions
Memory corruption in Core while processing control functions.
all versions
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains
IPPROTO_NONE as the nall versions
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
all versions
Transient DOS in WLAN Firmware while parsing a BTM request.
all versions
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
all versions
Memory corruption in Audio during playback with speaker protection.
all versions
Memory corruption in HLOS while running playready use-case.
all versions
Memory corruption when processing cmd parameters while parsing vdev.
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
all versions
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
all versions
Memory corruption while loading an ELF segment in TEE Kernel.
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
all versions
Information disclosure in WLAN HAL while handling command through WMI interfaces.
all versions
Information disclosure in WLAN HAL while handling the WMI state info command.
all versions
Information disclosure in IOE Firmware while handling WMI command.
all versions
Memory corruption in TZ Secure OS while loading an app ELF.
all versions
Memory Corruption in Core due to secure memory access by user while loading modem image.
all versions
Transient DOS in WLAN Firmware while parsing rsn ies.
all versions
Transient DOS in Modem while allocating DSM items.
all versions
Improper Access to the VM resource manager can lead to Memory Corruption.
all versions
Memory corruption in WLAN HAL while handling command through WMI interfaces.
all versions
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
all versions
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
all versions
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
all versions
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
all versions
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
all versions
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
all versions
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
all versions
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
all versions
Memory Corruption in Core Platform while printing the response buffer in log.
all versions
Memory corruption in Core Platform while printing the response buffer in log.
all versions
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
all versions
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
all versions
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
all versions
Transient DOS in WLAN Firmware while processing frames with missing header fields.
all versions
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
all versions
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
all versions
Information disclosure in Kernel due to indirect branch misprediction.
all versions
Memory corruption due to double free in Core while mapping HLOS address to the list.
all versions
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
all versions
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
all versions
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection
all versions
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
all versions
Memory corruption due to double free in core while initializing the encryption key.
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
all versions
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
all versions
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
all versions
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
all versions
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc respo
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
all versions
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
all versions
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
all versions
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory
all versions
Memory corruption due to stack-based buffer overflow in Core
all versions
Information disclosure due to buffer overread in Core
all versions
Information disclosure due to buffer overread in Core
all versions
Memory corruption in core due to stack-based buffer overflow
all versions
Memory corruption in Core due to stack-based buffer overflow.
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
all versions
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
all versions
Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto
all versions
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor tran
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
all versions
Transient DOS due to buffer over-read in WLAN firmware while processing PPE threshold. in Snapdragon Auto, Snapdragon Compute, Sna
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
all versions
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Comput
all versions
Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdrag
all versions
Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,
all versions
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon I
all versions
Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Au
all versions
memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity,
all versions
Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach
all versions
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon C
all versions
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Com
all versions
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdrago
all versions
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in S
all versions
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon
all versions
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon
all versions
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Sna
all versions
Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon A
all versions
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapd
all versions
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon
all versions
Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdr
all versions
Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto,
all versions
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon
all versions
Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Au
all versions
Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Aut
all versions
Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, S
all versions
Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon
all versions
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto,
all versions
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Sn
all versions
Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute,
all versions
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Sna
all versions
Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Snapdragon C
all versions
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon
all versions
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Compute, Snapdragon Conne
all versions
Possible race condition can occur due to lack of synchronization mechanism when On-Device Logging node open twice concurrently in
all versions
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdrag
all versions
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapd
all versions
Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
all versions
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Comput
all versions
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
all versions
Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in Snapdragon
all versions
Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snap
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
all versions
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Comput
all versions
Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Sn
all versions
Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Sna
all versions
Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information e
all versions
Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information e
all versions
Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN
all versions
Possible buffer overflow due to lack of length check of source and destination buffer before copying in Snapdragon Auto, Snapdrago
all versions
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
all versions
Improper access control in trusted application environment can cause unauthorized access to CDSP or ADSP VM memory with either pri
all versions
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon
all versions
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from
all versions
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
all versions
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
all versions
Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon
all versions
Possible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
all versions
Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Sn
all versions
Possible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon
all versions
Possible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snap
all versions
Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Com
all versions
Possible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute,
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
all versions
UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdr
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
all versions
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snap
all versions
Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon Auto, Snap
all versions
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon C
all versions
Integer underflow can occur when the RTCP length is lesser than the actual blocks present in Snapdragon Auto, Snapdragon Comp
all versions
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto,
all versions
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Comput
all versions
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Sna
all versions
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapd
all versions
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injectio
all versions
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
all versions
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdrag
all versions
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon
all versions
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Sna
all versions
Possible out of bound read due to lack of length check of Bandwidth-NSS IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
all versions
Use after free can occur due to improper handling of response from firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
all versions
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapd
all versions
Possible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapd
all versions
Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdra
all versions
Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon
all versions
Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
all versions
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon
all versions
Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapd
all versions
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdr
all versions
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute
all versions
Possible integer overflow in RPMB counter due to lack of length check on user provided data in Snapdragon Auto, Snapdragon Compute
all versions
Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
all versions
While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memory buffers
all versions
Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapd
all versions
Possible buffer overflow while updating ikev2 parameters for delete payloads received during informational exchange due to lack of
all versions
Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdra
all versions
While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap over
all versions
A race between command submission and destroying the context can cause an invalid context being added to the list leads to use aft
all versions
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdra
all versions
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdrago
all versions
Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attribute in Sn
all versions
Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for t
all versions
Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned up proper
all versions
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdragon Compute,
all versions
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdrag
all versions
Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snap
all versions
Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memor
all versions
Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the length of b
all versions
Resource leakage issue during dci client registration due to reference count is not decremented if dci client registration fails i
all versions
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame po
all versions
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN rangin
all versions
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon
all versions
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Com
all versions
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compu
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
all versions
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdra
all versions
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapd
all versions
Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial I
all versions
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdra
all versions
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length rece
all versions
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute,
all versions
Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, Snapdragon
all versions
Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon
all versions
Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory regio
all versions
Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto,
all versions
Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv
all versions
Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdra
all versions
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and r
all versions
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Au
all versions
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon A
all versions
Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdr
all versions
RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of
all versions
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread r
all versions
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute,
all versions
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon
all versions
Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdrago
all versions
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physica
all versions
Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto
all versions
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdrag
all versions
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Comp
all versions
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute,
all versions
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insuffi
all versions
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a sp
all versions
Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdr
all versions
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in
all versions
Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapd
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
all versions
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in
all versions
Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snap
all versions
Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto,
all versions
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snap
all versions
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclos
all versions
Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due
all versions
Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snap
all versions
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation
all versions
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapd
all versions
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version
all versions
Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Compute, Snapd
all versions
Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM
all versions
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Aut
all versions
Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon
all versions
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for par
all versions
Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage o
all versions
Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffe
all versions
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device loc
all versions
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction i
all versions
Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received
all versions
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdra
all versions
Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snap
all versions
While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key op
all versions
Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Com
all versions
Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Com
all versions
Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdr
all versions
Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon
all versions
Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdragon Compute,
all versions
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm kn
all versions
Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 in Snapdra
all versions
Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapdragon Auto
all versions
Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon Auto, Snap
all versions
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation. in Snapdr
all versions
Out of bound read and information disclosure in firmware due to insufficient checking of an embedded structure that can be sent fr
all versions
An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Comp
all versions
IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute, Snapdragon
all versions
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdra
all versions
While rendering the layout background, Error status check is not caught properly and also incorrect status handling is being done
all versions
While sending the rendered surface content to the screen, Error handling is not properly checked results in an unpredictable behav
all versions
Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto, Snapdrag
all versions
Lack of check of data type can lead to subsequent loop-expression potentially go negative and the condition will still evaluate to
all versions
Failure in taking appropriate action to handle the error case If keypad gpio deactivation fails leads to silent failure scenario a
all versions
Null pointer dereference during secure application termination using specific application ids. in Snapdragon Auto, Snapdragon Comp
all versions
Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdrago
all versions
Unauthorized access from GPU subsystem to HLOS or other non secure subsystem memory can lead to information disclosure in Snapdrag
all versions
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image load
all versions
Lack of check to prevent the buffer length taking negative values can lead to stack overflow. in Snapdragon Auto, Snapdragon Compu
all versions
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lo
all versions
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdrago
all versions
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdragon Auto,
all versions
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdragon Auto,
all versions
A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto, Snapdrago
all versions
Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon Compute, S
all versions
Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulting in unex
all versions
Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon Auto, Snap
all versions
While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if any key o
all versions
The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged applicat
all versions
Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decoding XTRA fi
all versions
Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electro
all versions
Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, S
all versions
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Cons
all versions
Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Comput
all versions
While updating blacklisting region shared buffered memory region is not validated against newly updated black list, causing boot-u
all versions
Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics
all versions
ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon C
all versions
Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
all versions
Lack of check on length parameter may cause buffer overflow while processing WMI commands in Snapdragon Auto, Snapdragon Compute,
all versions
Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage
all versions
TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics C
all versions
Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Co
all versions
Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Co
all versions
Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose continuity in Sn
all versions
Improper input validation in wireless service messaging module for data received from broadcast messages can lead to heap overflow
all versions
Improper input validation for argument received from HLOS can lead to buffer overflows and unexpected behavior in Snapdragon Auto,
all versions
Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdragon Auto,
all versions
Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
all versions
Improper access to HLOS is possible while transferring memory to CPZ in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
all versions
Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute, Snapdrago
all versions
Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto,
all versions
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdrag
all versions
Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a buffer overf
all versions
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snap
all versions
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPD
all versions
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt