Home/Product/qualcomm sdm429w firmware
Product

qualcomm sdm429w firmware

460 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-21385
all versions
Memory corruption while using alignments for memory allocation.
7.8HIGH
CVE-2025-47383
all versions
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
7.2HIGH
CVE-2025-47333
all versions
Memory corruption while handling buffer mapping operations in the cryptographic driver.
6.6MEDIUM
CVE-2025-47320
all versions
Memory corruption while processing MFC channel configuration during music playback.
7.8HIGH
CVE-2025-27074
all versions
Memory corruption while processing a GP command response.
8.8HIGH
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8HIGH
CVE-2025-21488
all versions
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
8.2HIGH
CVE-2025-21487
all versions
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than th
8.2HIGH
CVE-2025-21484
all versions
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP pa
8.2HIGH
CVE-2025-21483
all versions
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
9.8CRITICAL
CVE-2025-21482
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
7.1HIGH
CVE-2025-27071
all versions
Memory corruption while processing specific files in Powerline Communication Firmware.
7.3HIGH
CVE-2025-21433
all versions
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
6.2MEDIUM
CVE-2025-21427
all versions
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
8.2HIGH
CVE-2024-53026
all versions
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
8.2HIGH
CVE-2024-53021
all versions
Information disclosure may occur while processing goodbye RTCP packet from network.
8.2HIGH
CVE-2024-53020
all versions
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
8.2HIGH
CVE-2024-53019
all versions
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
8.2HIGH
CVE-2024-53018
all versions
Memory corruption may occur while processing the OIS packet parser.
6.6MEDIUM
CVE-2024-53017
all versions
Memory corruption while handling test pattern generator IOCTL command.
6.6MEDIUM
CVE-2024-53016
all versions
Memory corruption while processing I2C settings in Camera driver.
6.6MEDIUM
CVE-2024-53015
all versions
Memory corruption while processing IOCTL command to handle buffers associated with a session.
6.6MEDIUM
CVE-2024-53013
all versions
Memory corruption may occur while processing voice call registration with user.
6.6MEDIUM
CVE-2024-49847
all versions
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
7.5HIGH
CVE-2024-49844
all versions
Memory corruption while triggering commands in the PlayReady Trusted application.
7.8HIGH
CVE-2024-49842
all versions
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
7.8HIGH
CVE-2024-49830
all versions
Memory corruption while processing an IOCTL call to set mixer controls.
6.6MEDIUM
CVE-2024-49829
all versions
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
6.7MEDIUM
CVE-2024-45581
all versions
Memory corruption while sound model registration for voice activation with audio kernel driver.
6.6MEDIUM
CVE-2024-45579
all versions
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due
7.8HIGH
CVE-2024-45578
all versions
Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.
7.8HIGH
CVE-2024-45577
all versions
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
7.8HIGH
CVE-2024-45576
all versions
Memory corruption while prociesing command buffer in OPE module.
7.8HIGH
CVE-2024-45575
all versions
Memory corruption Camera kernel when large number of devices are attached through userspace.
7.8HIGH
CVE-2024-45574
all versions
Memory corruption during array access in Camera kernel due to invalid index from invalid command data.
7.8HIGH
CVE-2024-45570
all versions
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
6.6MEDIUM
CVE-2024-45568
all versions
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
6.7MEDIUM
CVE-2024-45567
all versions
Memory corruption while encoding JPEG format.
7.8HIGH
CVE-2024-45566
all versions
Memory corruption during concurrent buffer access due to modification of the reference count.
7.8HIGH
CVE-2024-45565
all versions
Memory corruption when blob structure is modified by user-space after kernel verification.
7.8HIGH
CVE-2024-45564
all versions
Memory corruption during concurrent access to server info object due to incorrect reference count update.
7.8HIGH
CVE-2024-45563
all versions
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding se
6.6MEDIUM
CVE-2024-45562
all versions
Memory corruption during concurrent access to server info object due to unprotected critical field.
6.6MEDIUM
CVE-2024-45554
all versions
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
7.8HIGH
CVE-2025-21430
all versions
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
7.5HIGH
CVE-2025-21429
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
7.5HIGH
CVE-2025-21428
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session
7.5HIGH
CVE-2024-45556
all versions
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
6.5MEDIUM
CVE-2024-45552
all versions
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to
8.2HIGH
CVE-2024-45549
all versions
Information disclosure while creating MQ channels.
7.7HIGH
CVE-2024-43067
all versions
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
7.8HIGH
CVE-2024-43066
all versions
Memory corruption while handling file descriptor during listener registration/de-registration.
7.8HIGH
CVE-2024-43065
all versions
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
7.1HIGH
CVE-2024-43046
all versions
There may be information disclosure during memory re-allocation in TZ Secure OS.
5.5MEDIUM
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-53024
all versions
Memory corruption in display driver while detaching a device.
7.8HIGH
CVE-2024-53023
all versions
Memory corruption may occur while accessing a variable during extended back to back tests.
7.8HIGH
CVE-2024-53014
all versions
Memory corruption may occur while validating ports and channels in Audio driver.
7.8HIGH
CVE-2024-49836
all versions
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
7.8HIGH
CVE-2024-45580
all versions
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
7.8HIGH
CVE-2024-43062
all versions
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
7.8HIGH
CVE-2024-43061
all versions
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is
7.8HIGH
CVE-2024-43060
all versions
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
7.8HIGH
CVE-2024-43059
all versions
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
7.8HIGH
CVE-2024-43057
all versions
Memory corruption while processing command in Glink linux.
7.8HIGH
CVE-2024-43056
all versions
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
5.5MEDIUM
CVE-2024-43055
all versions
Memory corruption while processing camera use case IOCTL call.
7.8HIGH
CVE-2024-38426
all versions
While processing the authentication message in UE, improper authentication may lead to information disclosure.
5.4MEDIUM
CVE-2024-49834
all versions
Memory corruption while power-up or power-down sequence of the camera sensor.
7.8HIGH
CVE-2024-49832
all versions
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
7.8HIGH
CVE-2024-45573
all versions
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
7.8HIGH
CVE-2024-45561
all versions
Memory corruption while handling IOCTL call from user-space to set latency level.
7.8HIGH
CVE-2024-45560
all versions
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
7.8HIGH
CVE-2024-38418
all versions
Memory corruption while parsing the memory map info in IOCTL calls.
7.8HIGH
CVE-2024-38417
all versions
Information disclosure while processing IO control commands.
6.1MEDIUM
CVE-2024-38404
all versions
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
7.5HIGH
CVE-2024-43064
all versions
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU
7.5HIGH
CVE-2024-33067
all versions
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound
6.1MEDIUM
CVE-2024-43053
all versions
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
7.8HIGH
CVE-2024-43052
all versions
Memory corruption while processing API calls to NPU with invalid input.
7.8HIGH
CVE-2024-43050
all versions
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
7.8HIGH
CVE-2024-43049
all versions
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
7.8HIGH
CVE-2024-43048
all versions
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
7.8HIGH
CVE-2024-33063
all versions
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this
7.5HIGH
CVE-2024-33056
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
8.4HIGH
CVE-2024-33044
all versions
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
8.4HIGH
CVE-2024-38424
all versions
Memory corruption during GNSS HAL process initialization.
7.8HIGH
CVE-2024-38423
all versions
Memory corruption while processing GPU page table switch.
7.8HIGH
CVE-2024-38422
all versions
Memory corruption while processing voice packet with arbitrary data received from ADSP.
7.8HIGH
CVE-2024-38410
all versions
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
7.8HIGH
CVE-2024-38409
all versions
Memory corruption while station LL statistic handling.
7.8HIGH
CVE-2024-38407
all versions
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
7.8HIGH
CVE-2024-38406
all versions
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
7.8HIGH
CVE-2024-38403
all versions
Transient DOS while parsing BTM ML IE when per STA profile is not included.
7.5HIGH
CVE-2024-33068
all versions
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5HIGH
CVE-2024-33031
all versions
Memory corruption while processing the update SIM PB records request.
6.7MEDIUM
CVE-2024-23386
all versions
memory corruption when WiFi display APIs are invoked with large random inputs.
6.7MEDIUM
CVE-2024-23385
all versions
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
7.5HIGH
CVE-2024-33060
all versions
Memory corruption when two threads try to map and unmap a single node simultaneously.
8.4HIGH
CVE-2024-33054
all versions
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
7.8HIGH
CVE-2024-33052
all versions
Memory corruption when user provides data for FM HCI command control operations.
7.8HIGH
CVE-2024-33048
all versions
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
7.5HIGH
CVE-2024-33047
all versions
Memory corruption when the captureRead QDCM command is invoked from user-space.
8.4HIGH
CVE-2024-33043
all versions
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
5.5MEDIUM
CVE-2024-33042
all versions
Memory corruption when Alternative Frequency offset value is set to 255.
7.8HIGH
CVE-2024-33016
all versions
memory corruption when an invalid firehose patch command is invoked.
6.8MEDIUM
CVE-2024-23365
all versions
Memory corruption while releasing shared resources in MinkSocket listener thread.
8.4HIGH
CVE-2024-23364
all versions
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of
7.5HIGH
CVE-2024-23359
all versions
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
8.2HIGH
CVE-2024-23358
all versions
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
7.5HIGH
CVE-2024-33027
all versions
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU
8.4HIGH
CVE-2024-23357
all versions
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
6.2MEDIUM
CVE-2024-23353
all versions
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5HIGH
CVE-2024-23368
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition.
7.8HIGH
CVE-2024-21461
all versions
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4HIGH
CVE-2023-43551
all versions
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immedia
9.1CRITICAL
CVE-2023-43528
all versions
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than
6.1MEDIUM
CVE-2023-43527
all versions
Information disclosure while parsing dts header atom in Video.
6.8MEDIUM
CVE-2024-21468
all versions
Memory corruption when there is failed unmap operation in GPU.
8.4HIGH
CVE-2023-33023
all versions
Memory corruption while processing finish_sign command to pass a rsp buffer.
8.4HIGH
CVE-2023-28547
all versions
Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4HIGH
CVE-2023-33066
all versions
Memory corruption in Audio while processing RT proxy port register driver.
8.4HIGH
CVE-2023-43513
all versions
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitr
7.8HIGH
CVE-2023-33069
all versions
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
6.7MEDIUM
CVE-2023-33068
all versions
Memory corruption in Audio while processing IIR config data from AFE calibration block.
6.7MEDIUM
CVE-2023-33067
all versions
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
6.7MEDIUM
CVE-2023-33065
all versions
Information disclosure in Audio while accessing AVCS services from ADSP payload.
6.1MEDIUM
CVE-2023-33064
all versions
Transient DOS in Audio when invoking callback function of ASM driver.
5.5MEDIUM
CVE-2023-33120
all versions
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
7.8HIGH
CVE-2023-33033
all versions
Memory corruption in Audio during playback with speaker protection.
8.4HIGH
CVE-2023-33030
all versions
Memory corruption in HLOS while running playready use-case.
9.3CRITICAL
CVE-2023-33107
all versions
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
8.4HIGH
CVE-2023-33070
all versions
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
7.1HIGH
CVE-2023-33063
all versions
Memory corruption in DSP Services during a remote call from HLOS to DSP.
7.8HIGH
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8HIGH
CVE-2023-28551
all versions
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8HIGH
CVE-2023-28550
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8HIGH
CVE-2023-28546
all versions
Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8HIGH
CVE-2023-33059
all versions
Memory corruption in Audio while processing the VOC packet data from ADSP.
7.8HIGH
CVE-2023-33031
all versions
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
7.8HIGH
CVE-2023-28570
all versions
Memory corruption while processing audio effects.
6.7MEDIUM
CVE-2023-24850
all versions
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
7.8HIGH
CVE-2023-24849
all versions
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
8.2HIGH
CVE-2023-24848
all versions
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
8.2HIGH
CVE-2023-22385
all versions
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
8.2HIGH
CVE-2023-33020
all versions
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
7.5HIGH
CVE-2023-33019
all versions
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE
7.5HIGH
CVE-2023-28537
all versions
Memory corruption while allocating memory in COmxApeDec module in Audio.
8.4HIGH
CVE-2023-22666
all versions
Memory Corruption in Audio while playing amrwbplus clips with modified content.
8.4HIGH
CVE-2023-21626
all versions
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
7.1HIGH
CVE-2022-40510
all versions
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
9.8CRITICAL
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8HIGH
CVE-2023-22667
all versions
Memory Corruption in Audio while allocating the ion buffer during the music playback.
8.4HIGH
CVE-2023-22387
all versions
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
7.8HIGH
CVE-2023-21670
all versions
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
7.8HIGH
CVE-2023-21669
all versions
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
8.2HIGH
CVE-2023-21661
all versions
Transient DOS while parsing WLAN beacon or probe-response frame.
7.5HIGH
CVE-2023-21659
all versions
Transient DOS in WLAN Firmware while processing frames with missing header fields.
7.5HIGH
CVE-2023-21658
all versions
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
7.5HIGH
CVE-2023-21657
all versions
Memoru corruption in Audio when ADSP sends input during record use case.
7.8HIGH
CVE-2023-21656
all versions
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
7.8HIGH
CVE-2022-40521
all versions
Transient DOS due to improper authorization in Modem
7.5HIGH
CVE-2022-33267
all versions
Memory corruption in Linux while sending DRM request.
6.7MEDIUM
CVE-2022-33264
all versions
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
7.9HIGH
CVE-2022-33227
all versions
Memory corruption in Linux android due to double free while calling unregister provider after register call.
6.7MEDIUM
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1HIGH
CVE-2023-21666
all versions
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
8.4HIGH
CVE-2023-21665
all versions
Memory corruption in Graphics while importing a file.
8.4HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4HIGH
CVE-2022-40503
all versions
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
8.2HIGH
CVE-2022-33302
all versions
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command le
6.8MEDIUM
CVE-2022-33289
all versions
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
6.8MEDIUM
CVE-2022-40537
all versions
Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
7.3HIGH
CVE-2022-40515
all versions
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
7.3HIGH
CVE-2022-33245
all versions
Memory corruption in WLAN due to use after free
6.7MEDIUM
CVE-2022-33242
all versions
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
7.8HIGH
CVE-2022-33213
all versions
Memory corruption in modem due to buffer overflow while processing a PPP packet
7.5HIGH
CVE-2022-25705
all versions
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
7.8HIGH
CVE-2022-25694
all versions
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
8.4HIGH
CVE-2022-22075
all versions
Information Disclosure in Graphics during GPU context switch.
6.2MEDIUM
CVE-2022-33280
all versions
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
7.3HIGH
CVE-2022-33248
all versions
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
7.8HIGH
CVE-2022-33243
all versions
Memory corruption due to improper access control in Qualcomm IPC.
8.4HIGH
CVE-2022-33233
all versions
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
7.8HIGH
CVE-2022-33225
all versions
Memory corruption due to use after free in trusted application environment.
6.7MEDIUM
CVE-2022-33266
all versions
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modif
5.9MEDIUM
CVE-2022-33255
all versions
Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from pe
8.2HIGH
CVE-2022-25721
all versions
Memory corruption in video driver due to type confusion error during video playback
6.7MEDIUM
CVE-2022-25717
all versions
Memory corruption in display due to double free while allocating frame buffer memory
6.7MEDIUM
CVE-2022-25715
all versions
Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields
6.7MEDIUM
CVE-2022-22088
all versions
Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote
9.8CRITICAL
CVE-2022-22079
all versions
Denial of service while processing fastboot flash command on mmc due to buffer over read
4.6MEDIUM
CVE-2022-33268
all versions
Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon
8.2HIGH
CVE-2022-25702
all versions
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Comp
7.5HIGH
CVE-2022-25698
all versions
Memory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon M
8.4HIGH
CVE-2022-25697
all versions
Memory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon
8.4HIGH
CVE-2022-25695
all versions
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto,
8.4HIGH
CVE-2022-25692
all versions
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2022-25685
all versions
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapd
7.5HIGH
CVE-2022-25682
all versions
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Sn
8.4HIGH
CVE-2022-25677
all versions
Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
6.7MEDIUM
CVE-2022-33234
all versions
Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdra
7.3HIGH
CVE-2022-25743
all versions
Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdr
8.4HIGH
CVE-2022-25741
all versions
Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdr
7.5HIGH
CVE-2022-25724
all versions
Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Sna
8.4HIGH
CVE-2022-25720
all versions
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdrag
9.8CRITICAL
CVE-2022-25719
all versions
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdrag
8.2HIGH
CVE-2022-25718
all versions
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Co
9.1CRITICAL
CVE-2022-25687
all versions
memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
7.3HIGH
CVE-2022-25666
all versions
Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon
6.7MEDIUM
CVE-2022-25664
all versions
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon
6.2MEDIUM
CVE-2022-25662
all versions
Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv
5.3MEDIUM
CVE-2022-22058
all versions
Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapd
8.4HIGH
CVE-2022-25706
all versions
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compu
8.2HIGH
CVE-2022-25688
all versions
Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.3HIGH
CVE-2022-25669
all versions
Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
7.5HIGH
CVE-2022-25654
all versions
Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connecti
6.7MEDIUM
CVE-2022-25653
all versions
Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity,
6.8MEDIUM
CVE-2022-22074
all versions
Memory Corruption during wma file playback due to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
8.4HIGH
CVE-2022-25668
all versions
Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
7.3HIGH
CVE-2022-25659
all versions
Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon Compute,
7.3HIGH
CVE-2022-25658
all versions
Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function in Snapdra
7.3HIGH
CVE-2022-22062
all versions
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Com
8.2HIGH
CVE-2021-35135
all versions
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
6.2MEDIUM
CVE-2021-35132
all versions
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Sna
8.4HIGH
CVE-2021-35122
all versions
Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdrago
9.3CRITICAL
CVE-2021-35113
all versions
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in S
7.3HIGH
CVE-2022-22087
all versions
memory corruption in video due to buffer overflow while parsing mkv clip with no codechecker in Snapdragon Auto, Snapdragon Comput
7.3HIGH
CVE-2022-22086
all versions
Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon C
7.3HIGH
CVE-2022-22085
all versions
Memory corruption in video due to buffer overflow while reading the dts file in Snapdragon Auto, Snapdragon Compute, Snapdragon Co
8.4HIGH
CVE-2022-22084
all versions
Memory corruption when extracting qcp audio file due to lack of check on data length in Snapdragon Auto, Snapdragon Compute, Snapd
8.4HIGH
CVE-2022-22083
all versions
Denial of service due to memory corruption while extracting ape header from clips in Snapdragon Auto, Snapdragon Compute, Snapdrag
7.5HIGH
CVE-2022-22082
all versions
Memory corruption due to possible buffer overflow while parsing DSF header with corrupted channel count in Snapdragon Auto, Snapdr
8.4HIGH
CVE-2022-22065
all versions
Out of bound read in WLAN HOST due to improper length check can lead to DOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
7.5HIGH
CVE-2022-22064
all versions
Possible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5HIGH
CVE-2021-35120
all versions
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Com
6.7MEDIUM
CVE-2021-35118
all versions
An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snap
6.7MEDIUM
CVE-2021-35116
all versions
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdrag
7.7HIGH
CVE-2021-35112
all versions
A user with user level permission can access graphics protected region due to improper access control in register configuration in
8.4HIGH
CVE-2021-35104
all versions
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compu
9.8CRITICAL
CVE-2021-35100
all versions
Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Comput
7.5HIGH
CVE-2021-35098
all versions
Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Sna
6.7MEDIUM
CVE-2021-35083
all versions
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Sna
8.2HIGH
CVE-2021-35072
all versions
Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snap
7.8HIGH
CVE-2021-30349
all versions
Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto
8.2HIGH
CVE-2021-30344
all versions
Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Comp
7.5HIGH
CVE-2021-30342
all versions
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received
9.1CRITICAL
CVE-2021-30341
all versions
Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapd
9.8CRITICAL
CVE-2021-30334
all versions
Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-35105
all versions
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, S
8.4HIGH
CVE-2021-30333
all versions
Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Sna
7.8HIGH
CVE-2021-35068
all versions
Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereferenc
8.4HIGH
CVE-2021-30323
all versions
Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute
7.8HIGH
CVE-2021-30318
all versions
Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute,
8.4HIGH
CVE-2021-30353
all versions
Improper validation of function pointer type with actual function signature can lead to assertion in Snapdragon Auto, Snapdragon C
7.5HIGH
CVE-2021-30330
all versions
Possible null pointer dereference due to improper validation of APE clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connec
7.5HIGH
CVE-2021-30300
all versions
Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and assigning a garbage value to choice w
7.5HIGH
CVE-2021-30351
all versions
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapd
9.8CRITICAL
CVE-2021-30337
all versions
Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdrago
8.4HIGH
CVE-2021-30335
all versions
Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Sn
8.4HIGH
CVE-2021-30289
all versions
Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdr
7.8HIGH
CVE-2021-30273
all versions
Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, S
7.5HIGH
CVE-2021-30272
all versions
Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon
7.3HIGH
CVE-2021-30271
all versions
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto,
7.3HIGH
CVE-2021-30270
all versions
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Sn
7.3HIGH
CVE-2021-30268
all versions
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Sna
7.8HIGH
CVE-2021-30262
all versions
Improper validation of a socket state when socket events are being sent to clients can lead to invalid access of memory in Snapdra
8.4HIGH
CVE-2021-30255
all versions
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapd
7.8HIGH
CVE-2021-30254
all versions
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdra
7.8HIGH
CVE-2021-1975
all versions
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Comput
9.8CRITICAL
CVE-2021-1973
all versions
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
7.8HIGH
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0CRITICAL
CVE-2021-30258
all versions
Possible buffer overflow due to improper size calculation of payload received in VR service in Snapdragon Auto, Snapdragon Compute
8.4HIGH
CVE-2021-1959
all versions
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
7.8HIGH
CVE-2021-1949
all versions
Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Com
8.4HIGH
CVE-2021-1936
all versions
Null pointer dereference can occur due to lack of null check for user provided input in Snapdragon Auto, Snapdragon Compute, Snapd
7.5HIGH
CVE-2021-30261
all versions
Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from
8.4HIGH
CVE-2021-1976
all versions
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2021-1947
all versions
Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Con
8.4HIGH
CVE-2021-1939
all versions
Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, S
8.4HIGH
CVE-2021-30295
all versions
Possible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon A
8.4HIGH
CVE-2021-1974
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
7.5HIGH
CVE-2021-1935
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
7.1HIGH
CVE-2021-1933
all versions
UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdr
9.8CRITICAL
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3HIGH
CVE-2021-1972
all versions
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2021-1916
all versions
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto,
9.8CRITICAL
CVE-2021-1914
all versions
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Comput
7.5HIGH
CVE-2021-1904
all versions
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Sna
6.2MEDIUM
CVE-2021-1955
all versions
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2021-1899
all versions
Possible buffer over read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial
4.6MEDIUM
CVE-2021-1890
all versions
Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-1889
all versions
Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
8.4HIGH
CVE-2021-1888
all versions
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-1886
all versions
Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapd
8.4HIGH
CVE-2020-11307
all versions
Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdrag
9.8CRITICAL
CVE-2020-11292
all versions
Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapd
7.8HIGH
CVE-2020-11267
all versions
Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdra
8.4HIGH
CVE-2020-11262
all versions
A race between command submission and destroying the context can cause an invalid context being added to the list leads to use aft
7.0HIGH
CVE-2020-11261
all versions
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdra
7.8HIGH
CVE-2020-11240
all versions
Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for t
7.8HIGH
CVE-2020-11239
all versions
Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned up proper
7.8HIGH
CVE-2020-11160
all versions
Resource leakage issue during dci client registration due to reference count is not decremented if dci client registration fails i
6.7MEDIUM
CVE-2021-1927
all versions
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Com
8.4HIGH
CVE-2021-1910
all versions
Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna
7.3HIGH
CVE-2021-1906
all versions
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdra
6.2MEDIUM
CVE-2021-1905
all versions
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapd
8.4HIGH
CVE-2021-1895
all versions
Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial I
6.8MEDIUM
CVE-2021-1891
all versions
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdra
8.4HIGH
CVE-2020-11294
all versions
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon
5.9MEDIUM
CVE-2020-11293
all versions
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length rece
5.1MEDIUM
CVE-2020-11289
all versions
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2020-11251
all versions
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon A
8.2HIGH
CVE-2020-11234
all versions
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread r
8.4HIGH
CVE-2020-11191
all versions
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute,
8.2HIGH
CVE-2020-11309
all versions
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon
7.8HIGH
CVE-2020-11299
all versions
Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
9.8CRITICAL
CVE-2020-11290
all versions
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snap
7.0HIGH
CVE-2020-11227
all versions
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdrag
9.8CRITICAL
CVE-2020-11226
all versions
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Comp
7.5HIGH
CVE-2020-11221
all versions
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insuffi
5.5MEDIUM
CVE-2020-11199
all versions
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in
5.5MEDIUM
CVE-2020-11192
all versions
Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapd
9.8CRITICAL
CVE-2020-11190
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
9.1CRITICAL
CVE-2020-11189
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
9.1CRITICAL
CVE-2020-11188
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
9.1CRITICAL
CVE-2020-11171
all versions
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Sna
9.1CRITICAL
CVE-2020-11166
all versions
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in
9.1CRITICAL
CVE-2020-11272
all versions
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version
9.8CRITICAL
CVE-2020-11269
all versions
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Aut
8.8HIGH
CVE-2020-11204
all versions
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for par
7.8HIGH
CVE-2020-11203
all versions
Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon
7.1HIGH
CVE-2020-11177
all versions
User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device loc
8.8HIGH
CVE-2020-11170
all versions
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction i
9.8CRITICAL
CVE-2020-3639
all versions
u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memo
9.8CRITICAL
CVE-2020-11196
all versions
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon A
9.8CRITICAL
CVE-2020-11193
all versions
u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Aut
9.8CRITICAL
CVE-2020-11168
all versions
u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range'
9.8CRITICAL
CVE-2020-11123
all versions
u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at get
5.5MEDIUM
CVE-2020-3696
all versions
u'Use after free while installing new security rule in ipcrtr as old one is deleted and this rule could still be in use for checki
7.8HIGH
CVE-2020-3693
all versions
u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snapdragon Aut
7.8HIGH
CVE-2020-3673
all versions
u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to valida
9.8CRITICAL
CVE-2020-3670
all versions
u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Information Element
9.1CRITICAL
CVE-2020-3657
all versions
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered
9.8CRITICAL
CVE-2020-3654
all versions
u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in S
9.8CRITICAL
CVE-2020-11174
all versions
u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdragon Auto,
7.8HIGH
CVE-2020-11173
all versions
u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon
7.0HIGH
CVE-2020-11164
all versions
u'Third-party app may also call the broadcasts in Perfdump and cause privilege escalation issue due to improper access control' in
7.8HIGH
CVE-2020-11162
all versions
u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI device side' in
7.8HIGH
CVE-2020-11125
all versions
u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devices' in Sna
7.8HIGH
CVE-2020-3656
all versions
Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI devices i
7.8HIGH
CVE-2020-3634
all versions
u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Sn
9.1CRITICAL
CVE-2020-3646
all versions
u'Buffer overflow seen as the destination buffer size is lesser than the source buffer size in video application' in Snapdragon Co
7.8HIGH
CVE-2020-3643
all versions
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Com
5.5MEDIUM
CVE-2020-3624
all versions
u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage in operatio
7.8HIGH
CVE-2020-3622
all versions
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated fo
7.8HIGH
CVE-2020-3621
all versions
u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size res
5.5MEDIUM
CVE-2020-3620
all versions
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport ca
5.5MEDIUM
CVE-2020-11128
all versions
u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in Snapdragon
7.8HIGH
CVE-2020-11118
all versions
u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2020-11116
all versions
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapd
9.8CRITICAL
CVE-2020-11115
all versions
u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in S
7.5HIGH
CVE-2019-14115
all versions
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which c
5.5MEDIUM
CVE-2019-14074
all versions
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon C
7.8HIGH
CVE-2019-13999
all versions
u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information
7.8HIGH
CVE-2019-13998
all versions
u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into mem
7.8HIGH
CVE-2019-13995
all versions
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to mem
7.8HIGH
CVE-2019-13994
all versions
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than
7.8HIGH
CVE-2019-10615
all versions
u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of
7.8HIGH
CVE-2019-10527
all versions
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address
7.8HIGH
CVE-2020-3699
all versions
Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in
9.8CRITICAL
CVE-2020-3698
all versions
Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Sn
9.8CRITICAL
CVE-2020-3688
all versions
Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto
9.8CRITICAL
CVE-2019-14101
all versions
Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than
7.1HIGH
CVE-2019-14099
all versions
Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdragon Auto,
7.8HIGH
CVE-2019-14093
all versions
Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snap
7.8HIGH
CVE-2019-10580
all versions
When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already fre
7.8HIGH
CVE-2020-3663
all versions
Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto,
9.8CRITICAL
CVE-2020-3662
all versions
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2020-3661
all versions
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due to lack o
9.8CRITICAL
CVE-2020-3660
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2020-3658
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.1CRITICAL
CVE-2020-3635
all versions
Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snapdragon Com
7.8HIGH
CVE-2020-3626
all versions
Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Co
7.8HIGH
CVE-2020-3614
all versions
Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdragon Auto,
9.8CRITICAL
CVE-2019-14094
all versions
Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdra
7.8HIGH
CVE-2019-14073
all versions
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overf
9.8CRITICAL
CVE-2019-14062
all versions
Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from network in Snap
9.8CRITICAL
CVE-2019-10626
all versions
Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snap
5.5MEDIUM
CVE-2020-3680
all versions
A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer
7.0HIGH
CVE-2020-3641
all versions
Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto,
9.8CRITICAL
CVE-2020-3633
all versions
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or n
9.8CRITICAL
CVE-2020-3630
all versions
Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Compute, Snap
7.8HIGH
CVE-2020-3610
all versions
Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as there is no
7.8HIGH
CVE-2019-14067
all versions
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channe
5.5MEDIUM
CVE-2019-14053
all versions
When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where the mode
7.1HIGH
CVE-2019-14039
all versions
Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Sn
7.1HIGH
CVE-2019-14038
all versions
Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in command respo
7.1HIGH
CVE-2020-3651
all versions
Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames. in Snapdr
7.5HIGH
CVE-2019-14127
all versions
Possible buffer overflow while playing mkv clip due to lack of validation of atom size buffer in Snapdragon Auto, Snapdragon Compu
9.8CRITICAL
CVE-2019-14070
all versions
Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdra
7.0HIGH
CVE-2019-14033
all versions
Multiple Read overflows issue due to improper length check while decoding tau reject/tau accept/detach request/attach reject/attac
9.1CRITICAL
CVE-2019-14021
all versions
Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filename length
7.8HIGH
CVE-2019-14020
all versions
Multiple Read overflows issue due to improper length check while decoding dedicated_eps_bearer_req/ act_def_context_req/ cs_serv_n
9.1CRITICAL
CVE-2019-14019
all versions
Multiple Read overflows issue due to improper length check while decoding RAU accept/PDN disconnect Rej/Modify EPS ctxt req/bearer
9.1CRITICAL
CVE-2019-14018
all versions
Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.8HIGH
CVE-2019-14011
all versions
Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ esm data t
9.1CRITICAL
CVE-2019-14001
all versions
Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Indu
7.8HIGH
CVE-2019-10625
all versions
Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in Snapdrago
7.1HIGH
CVE-2019-10610
all versions
Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media line in Sna
9.1CRITICAL
CVE-2019-10609
all versions
Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdragon Compu
9.8CRITICAL
CVE-2019-10588
all versions
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overf
9.8CRITICAL
CVE-2019-10574
all versions
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute,
7.1HIGH
CVE-2019-10556
all versions
Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer overflow
7.8HIGH
CVE-2019-10551
all versions
String error while processing non standard SIP messages received can lead to buffer overread and then denial of service in Snapdra
9.1CRITICAL
CVE-2019-10523
all versions
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Compute, Snap
5.5MEDIUM
CVE-2019-14095
all versions
Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specification in S
9.8CRITICAL
CVE-2019-14079
all versions
Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the firs
7.8HIGH
CVE-2019-14072
all versions
Unhandled paging request is observed due to dereferencing an already freed object because of race condition between sparse free an
7.0HIGH
CVE-2019-14068
all versions
Out of bound access in msm routing due to lack of check of size before accessing in Snapdragon Auto, Snapdragon Compute, Snapdrago
7.8HIGH
CVE-2019-14061
all versions
Null-pointer dereference can occur while accessing the segment element info when it is not allocated and assigned in Snapdragon Au
7.5HIGH
CVE-2019-14029
all versions
Use-after-free in graphics module due to destroying already queued syncobj in error case in Snapdragon Auto, Snapdragon Compute, S
7.8HIGH
CVE-2019-14000
all versions
Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption
7.8HIGH
CVE-2019-10594
all versions
Stack overflow can occur when SDP is received with multiple payload types in the FMTP attribute of a video M line in Snapdragon Au
9.8CRITICAL
CVE-2019-10593
all versions
Buffer overflow can occur when processing non standard SDP video Image attribute parameter in a VILTE\VOLTE call in Snapdragon Aut
9.8CRITICAL
CVE-2019-10591
all versions
Null pointer dereference can happen when parsing udta atom which is non-standard and having invalid depth in Snapdragon Auto, Snap
7.5HIGH
CVE-2019-10587
all versions
Possible Stack overflow can occur when processing a large SDP body or non standard SDP body without right delimiters in Snapdragon
9.8CRITICAL
CVE-2019-10586
all versions
Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdr
9.8CRITICAL
CVE-2019-10577
all versions
Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of s
9.1CRITICAL
CVE-2019-10554
all versions
Multiple Read overflows issue due to improper length check while decoding Identity Request in CSdomain/Authentication Reject in CS
9.1CRITICAL
CVE-2019-10553
all versions
Multiple Read overflows due to improper length checks while decoding authentication in Cs domain/RAU Reject and TC cmd in Snapdrag
9.1CRITICAL
CVE-2019-10552
all versions
Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cm
9.1CRITICAL
CVE-2019-10550
all versions
Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, S
9.1CRITICAL
CVE-2019-10549
all versions
Null pointer dereference issue can happen due to improper validation of CSEQ header response received from network in Snapdragon A
7.5HIGH
CVE-2019-14088
all versions
Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource protection
7.8HIGH
CVE-2019-14060
all versions
Uninitialized stack data gets used If memory is not allocated for blob or if the allocated blob is less than the struct size requi
7.8HIGH
CVE-2019-14057
all versions
Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Aut
9.1CRITICAL
CVE-2019-14055
all versions
Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer acc
7.8HIGH
CVE-2019-14041
all versions
During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating messag
7.8HIGH
CVE-2019-14040
all versions
Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown co
7.8HIGH
CVE-2019-14002
all versions
APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon
7.8HIGH
CVE-2019-10590
all versions
Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, S
9.8CRITICAL
CVE-2019-10567
all versions
There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing command
7.8HIGH
CVE-2019-14034
all versions
Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon Auto, Snapd
7.8HIGH
CVE-2019-14017
all versions
Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdrag
9.8CRITICAL
CVE-2019-14016
all versions
Integer overflow occurs while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
9.8CRITICAL
CVE-2019-14013
all versions
While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read in
9.8CRITICAL
CVE-2019-14006
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2019-14005
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdr
9.8CRITICAL
CVE-2019-14004
all versions
Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2019-14003
all versions
Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment information in Sna
7.5HIGH
CVE-2019-10611
all versions
Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon
9.8CRITICAL
CVE-2019-10585
all versions
Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use a
7.8HIGH
CVE-2019-10583
all versions
Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Compute, Sna
7.8HIGH
CVE-2019-10582
all versions
Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consum
7.8HIGH
CVE-2019-10579
all versions
Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon C
9.1CRITICAL
CVE-2019-10578
all versions
Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5HIGH
CVE-2019-10558
all versions
While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DS
7.8HIGH
CVE-2019-10548
all versions
While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occurs at same
7.8HIGH
CVE-2019-10532
all versions
Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Sna
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin