Home/Product/qualcomm sm7325 firmware
Product

qualcomm sm7325 firmware

105 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-33080
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5HIGH
CVE-2023-33079
all versions
Memory corruption in Audio while running invalid audio recording from ADSP.
7.8HIGH
CVE-2023-33063
all versions
Memory corruption in DSP Services during a remote call from HLOS to DSP.
7.8HIGH
CVE-2023-33054
all versions
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
9.1CRITICAL
CVE-2023-33044
all versions
Transient DOS in Data modem while handling TLB control messages from the Network.
7.5HIGH
CVE-2023-33042
all versions
Transient DOS in Modem after RRC Setup message is received.
7.5HIGH
CVE-2023-33022
all versions
Memory corruption in HLOS while invoking IOCTL calls from user-space.
8.4HIGH
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8HIGH
CVE-2023-33017
all versions
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
7.8HIGH
CVE-2023-33059
all versions
Memory corruption in Audio while processing the VOC packet data from ADSP.
7.8HIGH
CVE-2023-33055
all versions
Memory Corruption in Audio while invoking callback function in driver from ADSP.
7.8HIGH
CVE-2023-33035
all versions
Memory corruption while invoking callback function of AFE from ADSP.
7.8HIGH
CVE-2023-33034
all versions
Memory corruption while parsing the ADSP response command.
7.8HIGH
CVE-2023-33029
all versions
Memory corruption in DSP Service during a remote call from HLOS to DSP.
8.4HIGH
CVE-2023-33027
all versions
Transient DOS in WLAN Firmware while parsing rsn ies.
7.5HIGH
CVE-2023-33026
all versions
Transient DOS in WLAN Firmware while parsing a NAN management frame.
7.5HIGH
CVE-2023-28540
all versions
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
9.1CRITICAL
CVE-2023-21670
all versions
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
7.8HIGH
CVE-2023-21659
all versions
Transient DOS in WLAN Firmware while processing frames with missing header fields.
7.5HIGH
CVE-2023-21657
all versions
Memoru corruption in Audio when ADSP sends input during record use case.
7.8HIGH
CVE-2023-21656
all versions
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
7.8HIGH
CVE-2022-40536
all versions
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
7.5HIGH
CVE-2022-40533
all versions
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
6.2MEDIUM
CVE-2022-40529
all versions
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
7.1HIGH
CVE-2022-40523
all versions
Information disclosure in Kernel due to indirect branch misprediction.
7.1HIGH
CVE-2022-40521
all versions
Transient DOS due to improper authorization in Modem
7.5HIGH
CVE-2022-40507
all versions
Memory corruption due to double free in Core while mapping HLOS address to the list.
8.4HIGH
CVE-2022-33264
all versions
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
7.9HIGH
CVE-2022-33251
all versions
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
7.5HIGH
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1HIGH
CVE-2022-22060
all versions
Assertion occurs while processing Reconfiguration message due to improper validation
7.5HIGH
CVE-2022-40504
all versions
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
7.5HIGH
CVE-2023-21665
all versions
Memory corruption in Graphics while importing a file.
8.4HIGH
CVE-2022-34144
all versions
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
7.5HIGH
CVE-2022-33305
all versions
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
7.5HIGH
CVE-2023-21630
all versions
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
8.4HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4HIGH
CVE-2022-40503
all versions
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
8.2HIGH
CVE-2022-33302
all versions
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command le
6.8MEDIUM
CVE-2022-33289
all versions
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
6.8MEDIUM
CVE-2022-33288
all versions
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection
9.3CRITICAL
CVE-2022-33270
all versions
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
7.5HIGH
CVE-2022-33231
all versions
Memory corruption due to double free in core while initializing the encryption key.
9.3CRITICAL
CVE-2022-22080
all versions
Improper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Sna
8.4HIGH
CVE-2021-30284
all versions
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto
7.5HIGH
CVE-2021-30266
all versions
Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon
6.7MEDIUM
CVE-2021-30264
all versions
Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon
6.7MEDIUM
CVE-2021-30259
all versions
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdrag
7.8HIGH
CVE-2021-30255
all versions
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapd
7.8HIGH
CVE-2021-30254
all versions
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdra
7.8HIGH
CVE-2021-1982
all versions
Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Co
7.5HIGH
CVE-2021-1981
all versions
Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snapdragon Aut
7.5HIGH
CVE-2021-1979
all versions
Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Conn
7.8HIGH
CVE-2021-1975
all versions
Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdragon Comput
9.8CRITICAL
CVE-2021-1973
all versions
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
7.8HIGH
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0CRITICAL
CVE-2021-1921
all versions
Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in Snapdragon
7.8HIGH
CVE-2021-1903
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
5.3MEDIUM
CVE-2021-30316
all versions
Possible out of bound memory access due to improper boundary check while creating HSYNC fence in Snapdragon Auto, Snapdragon Conne
8.4HIGH
CVE-2021-30312
all versions
Improper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2021-30306
all versions
Possible buffer over read due to improper buffer allocation for file length passed from user space in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-30305
all versions
Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Conne
8.4HIGH
CVE-2021-30302
all versions
Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Comput
7.5HIGH
CVE-2021-30297
all versions
Possible out of bound read due to improper validation of packet length while handling data transfer in VR service in Snapdragon Au
8.4HIGH
CVE-2021-30292
all versions
Possible memory corruption due to lack of validation of client data used for memory allocation in Snapdragon Auto, Snapdragon Comp
8.4HIGH
CVE-2021-30291
all versions
Possible memory corruption due to lack of validation of client data used for memory allocation in Snapdragon Auto, Snapdragon Comp
8.4HIGH
CVE-2021-30288
all versions
Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Sn
8.4HIGH
CVE-2021-30258
all versions
Possible buffer overflow due to improper size calculation of payload received in VR service in Snapdragon Auto, Snapdragon Compute
8.4HIGH
CVE-2021-30257
all versions
Possible out of bound read or write in VR service due to lack of validation of DSP selection values in Snapdragon Compute, Snapdra
8.4HIGH
CVE-2021-30256
all versions
Possible stack overflow due to improper validation of camera name length before copying the name in VR Service in Snapdragon Compu
8.4HIGH
CVE-2021-1985
all versions
Possible buffer over read due to lack of data length check in QVR Service configuration in Snapdragon Auto, Snapdragon Compute, Sn
8.4HIGH
CVE-2021-1984
all versions
Possible buffer overflow due to improper validation of index value while processing the plugin block in Snapdragon Auto, Snapdrago
8.4HIGH
CVE-2021-1983
all versions
Possible buffer overflow due to improper handling of negative data length while processing write request in VR service in Snapdrag
8.4HIGH
CVE-2021-1980
all versions
Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Sna
7.5HIGH
CVE-2021-1977
all versions
Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Sna
7.5HIGH
CVE-2021-1967
all versions
Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN
5.3MEDIUM
CVE-2021-1959
all versions
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
7.8HIGH
CVE-2021-1949
all versions
Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Com
8.4HIGH
CVE-2021-1936
all versions
Null pointer dereference can occur due to lack of null check for user provided input in Snapdragon Auto, Snapdragon Compute, Snapd
7.5HIGH
CVE-2021-1917
all versions
Null pointer dereference can occur due to memory allocation failure in DIAG in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
8.4HIGH
CVE-2021-1913
all versions
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-30260
all versions
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist
8.4HIGH
CVE-2021-1976
all versions
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2021-1939
all versions
Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, S
8.4HIGH
CVE-2021-30295
all versions
Possible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon A
8.4HIGH
CVE-2021-30294
all versions
Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon Auto, Snap
8.4HIGH
CVE-2021-30290
all versions
Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Snapdragon Au
8.4HIGH
CVE-2021-1974
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
7.5HIGH
CVE-2021-1963
all versions
Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon
6.7MEDIUM
CVE-2021-1961
all versions
Possible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute
6.7MEDIUM
CVE-2021-1960
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
6.5MEDIUM
CVE-2021-1958
all versions
A race condition in fastrpc kernel driver for dynamic process creation can lead to use after free scenario in Snapdragon Auto, Sna
6.7MEDIUM
CVE-2021-1952
all versions
Possible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.8HIGH
CVE-2021-1948
all versions
Possible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snap
7.5HIGH
CVE-2021-1946
all versions
Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2021-1935
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
7.1HIGH
CVE-2021-1934
all versions
Possible memory corruption due to improper check when application loader object is explicitly destructed while application is unlo
8.4HIGH
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3HIGH
CVE-2021-1972
all versions
Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2021-1930
all versions
Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdrag
5.5MEDIUM
CVE-2021-1929
all versions
Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connec
6.2MEDIUM
CVE-2021-1923
all versions
Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon Auto, Snap
7.8HIGH
CVE-2021-1904
all versions
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Sna
6.2MEDIUM
CVE-2020-11301
all versions
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapd
9.1CRITICAL
CVE-2020-11264
all versions
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injectio
9.1CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin