threat
engine
.sh
Back
·
··:··
Home
/
Product
/
qualcomm sdm850 firmware
Product
qualcomm sdm850 firmware
142 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2022-40504
all versions
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
7.5
HIGH
CVE-2022-33273
all versions
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
7.3
HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4
HIGH
CVE-2022-33302
all versions
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command le
6.8
MEDIUM
CVE-2022-33289
all versions
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
6.8
MEDIUM
CVE-2022-33288
all versions
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection
9.3
CRITICAL
CVE-2022-33269
all versions
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
9.3
CRITICAL
CVE-2022-33231
all versions
Memory corruption due to double free in core while initializing the encryption key.
9.3
CRITICAL
CVE-2021-30327
all versions
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile,
7.5
HIGH
CVE-2020-3639
all versions
u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memo
9.8
CRITICAL
CVE-2020-11207
all versions
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Com
7.8
HIGH
CVE-2020-11206
all versions
Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdrago
7.8
HIGH
CVE-2020-11132
all versions
u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, S
7.1
HIGH
CVE-2020-11127
all versions
u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validati
7.8
HIGH
CVE-2020-11123
all versions
u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at get
5.5
MEDIUM
CVE-2020-3704
all versions
u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device may lead per
7.5
HIGH
CVE-2020-3690
all versions
u'Due to an incorrect SMMU configuration, the modem crypto engine can potentially compromise the hypervisor' in Snapdragon Auto, S
7.8
HIGH
CVE-2020-3684
all versions
u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader and applie
7.8
HIGH
CVE-2020-3670
all versions
u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Information Element
9.1
CRITICAL
CVE-2020-3634
all versions
u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Sn
9.1
CRITICAL
CVE-2020-3669
all versions
u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Snapdragon Co
9.8
CRITICAL
CVE-2020-3668
all versions
u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in S
9.8
CRITICAL
CVE-2020-3667
all versions
u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdrago
9.8
CRITICAL
CVE-2020-3666
all versions
u'Out of bounds memory access during memory copy while processing Host command' in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.8
HIGH
CVE-2020-3644
all versions
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in
5.5
MEDIUM
CVE-2020-3643
all versions
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Com
5.5
MEDIUM
CVE-2020-3624
all versions
u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage in operatio
7.8
HIGH
CVE-2020-3622
all versions
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated fo
7.8
HIGH
CVE-2020-3621
all versions
u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size res
5.5
MEDIUM
CVE-2020-3620
all versions
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport ca
5.5
MEDIUM
CVE-2020-3619
all versions
u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or memory cor
7.0
HIGH
CVE-2020-3611
all versions
u'XBL SEC clears only ZI region when loading Qualcomm-signed segments can lead to improper access issue' in Snapdragon Compute, Sn
7.8
HIGH
CVE-2020-11133
all versions
u'Possible out of bound array write in rxdco cal utility due to lack of array bound check' in Snapdragon Compute, Snapdragon Consu
7.8
HIGH
CVE-2019-14115
all versions
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which c
5.5
MEDIUM
CVE-2019-14074
all versions
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon C
7.8
HIGH
CVE-2019-14065
all versions
u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2019-14056
all versions
u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snap
7.8
HIGH
CVE-2019-14052
all versions
u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdr
9.8
CRITICAL
CVE-2019-13999
all versions
u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information
7.8
HIGH
CVE-2019-13998
all versions
u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into mem
7.8
HIGH
CVE-2019-13995
all versions
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to mem
7.8
HIGH
CVE-2019-13994
all versions
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than
7.8
HIGH
CVE-2019-13992
all versions
u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in Snapdragon
7.8
HIGH
CVE-2019-10629
all versions
u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdragon Comput
7.8
HIGH
CVE-2019-10628
all versions
u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' in Snapdra
7.8
HIGH
CVE-2019-10615
all versions
u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of
7.8
HIGH
CVE-2019-10596
all versions
u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Snapdragon Au
7.8
HIGH
CVE-2019-10562
all versions
u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies t
7.8
HIGH
CVE-2019-10527
all versions
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address
7.8
HIGH
CVE-2019-14101
all versions
Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than
7.1
HIGH
CVE-2019-14094
all versions
Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdra
7.8
HIGH
CVE-2019-14080
all versions
Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdragon Auto, Sn
9.8
CRITICAL
CVE-2019-14076
all versions
Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Snapdragon A
7.8
HIGH
CVE-2019-14073
all versions
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overf
9.8
CRITICAL
CVE-2019-14062
all versions
Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from network in Snap
9.8
CRITICAL
CVE-2019-10597
all versions
kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2020-3645
all versions
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdr
7.5
HIGH
CVE-2019-14077
all versions
Out of bound memory access while processing ese transmit command due to passing Response buffer received from user in Snapdragon A
7.8
HIGH
CVE-2019-14067
all versions
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channe
5.5
MEDIUM
CVE-2019-14054
all versions
Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boo
7.8
HIGH
CVE-2019-14043
all versions
Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto, Snapdrag
7.1
HIGH
CVE-2019-14042
all versions
Out of bound read in fingerprint application due to requested data assigned to a local buffer without length check in Snapdrago
7.1
HIGH
CVE-2020-3653
all versions
Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Sn
9.1
CRITICAL
CVE-2020-3652
all versions
Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check
9.1
CRITICAL
CVE-2019-14135
all versions
Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snapdragon Com
7.8
HIGH
CVE-2019-14134
all versions
Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of co
9.8
CRITICAL
CVE-2019-14114
all versions
Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snapdragon Aut
9.8
CRITICAL
CVE-2019-14113
all versions
Buffer overflow can occur in WLAN firmware while unwraping data using CCMP cipher suite during parsing of EAPOL handshake frame
9.8
CRITICAL
CVE-2019-14112
all versions
Potential buffer overflow while processing CBF frames due to lack of check of buffer length before copy in Snapdragon Auto, Snapdr
9.8
CRITICAL
CVE-2019-14110
all versions
Buffer overflow can occur in function wlan firmware while copying association frame content if frame length is more than the maxim
9.8
CRITICAL
CVE-2019-14033
all versions
Multiple Read overflows issue due to improper length check while decoding tau reject/tau accept/detach request/attach reject/attac
9.1
CRITICAL
CVE-2019-14022
all versions
Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, Snapdragon
7.5
HIGH
CVE-2019-14021
all versions
Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filename length
7.8
HIGH
CVE-2019-14020
all versions
Multiple Read overflows issue due to improper length check while decoding dedicated_eps_bearer_req/ act_def_context_req/ cs_serv_n
9.1
CRITICAL
CVE-2019-14019
all versions
Multiple Read overflows issue due to improper length check while decoding RAU accept/PDN disconnect Rej/Modify EPS ctxt req/bearer
9.1
CRITICAL
CVE-2019-14018
all versions
Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.8
HIGH
CVE-2019-14012
all versions
Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while proce
7.5
HIGH
CVE-2019-14011
all versions
Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/ esm data t
9.1
CRITICAL
CVE-2019-14009
all versions
Out of bound memory access while processing TZ command handler due to improper input validation on response length received from u
7.8
HIGH
CVE-2019-14007
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.5
MEDIUM
CVE-2019-10610
all versions
Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media line in Sna
9.1
CRITICAL
CVE-2019-10609
all versions
Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdragon Compu
9.8
CRITICAL
CVE-2019-10588
all versions
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overf
9.8
CRITICAL
CVE-2019-10575
all versions
Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Sn
7.8
HIGH
CVE-2019-10574
all versions
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute,
7.1
HIGH
CVE-2019-10551
all versions
String error while processing non standard SIP messages received can lead to buffer overread and then denial of service in Snapdra
9.1
CRITICAL
CVE-2019-10483
all versions
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snap
5.5
MEDIUM
CVE-2019-2311
all versions
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapdragon Auto
9.8
CRITICAL
CVE-2019-2300
all versions
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in Snapdragon
9.8
CRITICAL
CVE-2019-14097
all versions
Possible buffer overflow in WLAN Parser due to lack of length check when copying data in Snapdragon Auto, Snapdragon Compute, Snap
9.8
CRITICAL
CVE-2019-14095
all versions
Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specification in S
9.8
CRITICAL
CVE-2019-14086
all versions
Possible integer overflow while checking the length of frame which is a 32 bit integer and is added to another 32 bit integer whic
9.8
CRITICAL
CVE-2019-14085
all versions
Possible Integer underflow in WLAN function due to lack of check of data received from user side in Snapdragon Auto, Snapdragon Co
7.8
HIGH
CVE-2019-14083
all versions
While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is
9.8
CRITICAL
CVE-2019-14081
all versions
Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snapdragon Com
7.1
HIGH
CVE-2019-14071
all versions
Compromised reset handler may bypass access control due to AC config is being reset if debug path is enabled to collect secure or
7.8
HIGH
CVE-2019-14050
all versions
Out-of-bound writes occurs due to lack of check of buffer size will cause buffer overflow only in 32bit architecture. in Snapdrago
7.8
HIGH
CVE-2019-14031
all versions
Buffer overflow can occur while parsing RSN IE containing list of PMK ID`s which are more than the buffer size in Snapdragon Auto,
9.8
CRITICAL
CVE-2019-14030
all versions
The size of a buffer is determined by addition and multiplications operations that have the potential to overflow due to lack of b
7.8
HIGH
CVE-2019-14028
all versions
Buffer overwrite during memcpy due to lack of check on SSID length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.8
HIGH
CVE-2019-14027
all versions
Buffer overflow due to lack of upper bound check on channel length which is used for a loop. in Snapdragon Compute, Snapdragon Con
7.8
HIGH
CVE-2019-14026
all versions
Possible buffer overflow in WLAN WMI handler due to lack of ssid length check when copying data in Snapdragon Auto, Snapdragon Com
7.8
HIGH
CVE-2019-14015
all versions
A stack-based buffer overflow exists in the initialization of the identification stage due to lack of check on the number of templ
7.8
HIGH
CVE-2019-14000
all versions
Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption
7.8
HIGH
CVE-2019-10612
all versions
UTCB object has a function pointer called by the reaper to deallocate its memory resources and this address can potentially be cor
9.8
CRITICAL
CVE-2019-10594
all versions
Stack overflow can occur when SDP is received with multiple payload types in the FMTP attribute of a video M line in Snapdragon Au
9.8
CRITICAL
CVE-2019-10593
all versions
Buffer overflow can occur when processing non standard SDP video Image attribute parameter in a VILTE\VOLTE call in Snapdragon Aut
9.8
CRITICAL
CVE-2019-10587
all versions
Possible Stack overflow can occur when processing a large SDP body or non standard SDP body without right delimiters in Snapdragon
9.8
CRITICAL
CVE-2019-10586
all versions
Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdr
9.8
CRITICAL
CVE-2019-10577
all versions
Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of s
9.1
CRITICAL
CVE-2019-10554
all versions
Multiple Read overflows issue due to improper length check while decoding Identity Request in CSdomain/Authentication Reject in CS
9.1
CRITICAL
CVE-2019-10553
all versions
Multiple Read overflows due to improper length checks while decoding authentication in Cs domain/RAU Reject and TC cmd in Snapdrag
9.1
CRITICAL
CVE-2019-10552
all versions
Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cm
9.1
CRITICAL
CVE-2019-10550
all versions
Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, S
9.1
CRITICAL
CVE-2019-10546
all versions
Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto, Snapdrago
9.8
CRITICAL
CVE-2019-2267
all versions
Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in Snapdragon
7.8
HIGH
CVE-2019-2274
all versions
Improper Access Control for RPU write access from secure processor in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Ele
7.8
HIGH
CVE-2019-2242
all versions
Device memory may get corrupted because of buffer overflow/underflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer
9.8
CRITICAL
CVE-2019-10525
all versions
Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB in Snapdr
9.8
CRITICAL
CVE-2019-10516
all versions
Multiple read overflows in MM while decoding service accept,service reject,attach reject and MT detach in Snapdragon Auto, Snapdra
9.8
CRITICAL
CVE-2019-10513
all versions
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snap
5.5
MEDIUM
CVE-2019-10500
all versions
While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Snapdragon A
9.8
CRITICAL
CVE-2019-10487
all versions
Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Snapdragon Au
9.8
CRITICAL
CVE-2019-10482
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.9
MEDIUM
CVE-2019-2338
all versions
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure
7.1
HIGH
CVE-2019-2337
all versions
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause
7.5
HIGH
CVE-2019-2321
all versions
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Au
7.8
HIGH
CVE-2019-2320
all versions
Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Comp
9.8
CRITICAL
CVE-2019-2319
all versions
HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd
7.8
HIGH
CVE-2019-2288
all versions
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Au
7.8
HIGH
CVE-2019-10511
all versions
Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum
9.8
CRITICAL
CVE-2019-10493
all versions
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdra
9.8
CRITICAL
CVE-2019-10485
all versions
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons
7.5
HIGH
CVE-2019-2339
all versions
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdr
7.8
HIGH
CVE-2019-2335
all versions
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdr
7.5
HIGH
CVE-2019-2315
all versions
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure enviro
7.8
HIGH
CVE-2019-2303
all versions
SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute
9.8
CRITICAL
CVE-2019-2295
all versions
Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Snapdragon C
5.5
MEDIUM
CVE-2019-2289
all versions
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon A
9.8
CRITICAL
CVE-2019-2271
all versions
Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdrag
9.8
CRITICAL
CVE-2019-2251
all versions
If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially cause stack bu
7.8
HIGH
CVE-2018-13916
all versions
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data
7.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin