Home/Product/qualcomm sm8635p firmware
Product

qualcomm sm8635p firmware

117 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24082
all versions
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
7.8HIGH
CVE-2025-47404
all versions
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
6.5MEDIUM
CVE-2025-47403
all versions
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
6.5MEDIUM
CVE-2025-47401
all versions
Transient DOS when processing target power rate tables during channel configuration.
6.5MEDIUM
CVE-2026-21381
all versions
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness netwo
7.6HIGH
CVE-2026-21367
all versions
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
7.6HIGH
CVE-2025-47392
all versions
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
8.8HIGH
CVE-2025-47391
all versions
Memory corruption while processing a frame request from user.
7.8HIGH
CVE-2025-47389
all versions
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
7.8HIGH
CVE-2026-21385
all versions
Memory corruption while using alignments for memory allocation.
7.8HIGH
CVE-2025-59600
all versions
Memory Corruption when adding user-supplied data without checking available buffer space.
7.8HIGH
CVE-2025-47386
all versions
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
7.8HIGH
CVE-2025-47383
all versions
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
7.2HIGH
CVE-2025-47379
all versions
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocati
7.8HIGH
CVE-2025-47377
all versions
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
7.8HIGH
CVE-2025-47376
all versions
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
7.8HIGH
CVE-2025-47375
all versions
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
7.8HIGH
CVE-2025-47373
all versions
Memory Corruption when accessing buffers with invalid length during TA invocation.
7.8HIGH
CVE-2025-47371
all versions
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
6.5MEDIUM
CVE-2025-47402
all versions
Transient DOS when processing a received frame with an excessively large authentication information element.
6.5MEDIUM
CVE-2025-47398
all versions
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
7.8HIGH
CVE-2025-47397
all versions
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
7.8HIGH
CVE-2025-47366
all versions
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
7.1HIGH
CVE-2025-47369
all versions
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
5.5MEDIUM
CVE-2025-47348
all versions
Memory corruption while processing identity credential operations in the trusted application.
7.8HIGH
CVE-2025-47346
all versions
Memory corruption while processing a secure logging command in the trusted application.
7.8HIGH
CVE-2025-47345
all versions
Cryptographic issue may occur while encrypting license data.
8.4HIGH
CVE-2025-47344
all versions
Memory corruption while handling sensor utility operations.
6.7MEDIUM
CVE-2025-47339
all versions
Memory corruption while deinitializing a HDCP session.
7.8HIGH
CVE-2025-47337
all versions
Memory corruption while accessing a synchronization object during concurrent operations.
6.7MEDIUM
CVE-2025-47335
all versions
Memory corruption while parsing clock configuration data for a specific hardware type.
6.7MEDIUM
CVE-2025-47334
all versions
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
6.7MEDIUM
CVE-2025-47333
all versions
Memory corruption while handling buffer mapping operations in the cryptographic driver.
6.6MEDIUM
CVE-2025-47332
all versions
Memory corruption while processing a config call from userspace.
6.7MEDIUM
CVE-2025-47331
all versions
Information disclosure while processing a firmware event.
6.1MEDIUM
CVE-2025-47330
all versions
Transient DOS while parsing video packets received from the video firmware.
5.5MEDIUM
CVE-2025-47382
all versions
Memory corruption while loading an invalid firmware in boot loader.
7.8HIGH
CVE-2025-47323
all versions
Memory corruption while routing GPR packets between user and root when handling large data packet.
7.8HIGH
CVE-2025-47320
all versions
Memory corruption while processing MFC channel configuration during music playback.
7.8HIGH
CVE-2025-47319
all versions
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
6.7MEDIUM
CVE-2025-47370
all versions
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
6.5MEDIUM
CVE-2025-27070
all versions
Memory corruption while performing encryption and decryption commands.
7.8HIGH
CVE-2025-27054
all versions
Memory corruption while processing a malformed license file during reboot.
7.8HIGH
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8HIGH
CVE-2025-47317
all versions
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
7.8HIGH
CVE-2025-27034
all versions
Memory corruption while selecting the PLMN from SOR failed list.
9.8CRITICAL
CVE-2025-27033
all versions
Information disclosure while running video usecase having rogue firmware.
6.1MEDIUM
CVE-2025-27032
all versions
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
7.8HIGH
CVE-2025-21488
all versions
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
8.2HIGH
CVE-2025-21487
all versions
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than th
8.2HIGH
CVE-2025-21483
all versions
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
9.8CRITICAL
CVE-2025-21482
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
7.1HIGH
CVE-2025-21481
all versions
Memory corruption while performing private key encryption in trusted application.
7.8HIGH
CVE-2025-21476
all versions
Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
7.8HIGH
CVE-2025-27073
all versions
Transient DOS while creating NDP instance.
7.5HIGH
CVE-2025-27066
all versions
Transient DOS while processing an ANQP message.
7.5HIGH
CVE-2025-27065
all versions
Transient DOS while processing a frame with malformed shared-key descriptor.
7.5HIGH
CVE-2025-27062
all versions
Memory corruption while handling client exceptions, allowing unauthorized channel access.
7.8HIGH
CVE-2025-21477
all versions
Transient DOS while processing CCCH data when NW sends data with invalid length.
7.5HIGH
CVE-2025-21465
all versions
Information disclosure while processing the hash segment in an MBN file.
6.5MEDIUM
CVE-2025-21464
all versions
Information disclosure while reading data from an image using specified offset and size parameters.
6.5MEDIUM
CVE-2025-21461
all versions
Memory corruption when programming registers through virtual CDM.
7.8HIGH
CVE-2025-27061
all versions
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmwar
7.8HIGH
CVE-2025-27057
all versions
Transient DOS while handling beacon frames with invalid IE header length.
7.5HIGH
CVE-2025-27052
all versions
Memory corruption while processing data packets in diag received from Unix clients.
7.8HIGH
CVE-2025-27043
all versions
Memory corruption while processing manipulated payload in video firmware.
7.8HIGH
CVE-2025-27042
all versions
Memory corruption while processing video packets received from video firmware.
7.8HIGH
CVE-2025-21454
all versions
Transient DOS while processing received beacon frame.
7.5HIGH
CVE-2025-21450
all versions
Cryptographic issue occurs due to use of insecure connection method while downloading.
9.1CRITICAL
CVE-2025-21449
all versions
Transient DOS may occur while processing malformed length field in SSID IEs.
7.5HIGH
CVE-2025-21446
all versions
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
7.5HIGH
CVE-2025-21433
all versions
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
6.2MEDIUM
CVE-2025-21432
all versions
Memory corruption while retrieving the CBOR data from TA.
7.8HIGH
CVE-2025-21422
all versions
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
7.1HIGH
CVE-2025-21479
all versions
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
8.6HIGH
CVE-2025-21480
all versions
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
8.6HIGH
CVE-2025-21463
all versions
Transient DOS while processing the EHT operation IE in the received beacon frame.
7.5HIGH
CVE-2024-53026
all versions
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
8.2HIGH
CVE-2024-53021
all versions
Information disclosure may occur while processing goodbye RTCP packet from network.
8.2HIGH
CVE-2024-53020
all versions
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
8.2HIGH
CVE-2024-53019
all versions
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
8.2HIGH
CVE-2024-53015
all versions
Memory corruption while processing IOCTL command to handle buffers associated with a session.
6.6MEDIUM
CVE-2025-21468
all versions
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null
7.8HIGH
CVE-2025-21459
all versions
Transient DOS while parsing per STA profile in ML IE.
7.5HIGH
CVE-2025-21453
all versions
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures oc
7.8HIGH
CVE-2024-49847
all versions
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
7.5HIGH
CVE-2024-49845
all versions
Memory corruption during the FRS UDS generation process.
7.8HIGH
CVE-2024-49844
all versions
Memory corruption while triggering commands in the PlayReady Trusted application.
7.8HIGH
CVE-2024-49835
all versions
Memory corruption while reading secure file.
7.8HIGH
CVE-2025-21448
all versions
Transient DOS may occur while parsing SSID in action frames.
7.5HIGH
CVE-2025-21434
all versions
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
7.5HIGH
CVE-2024-49848
all versions
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
6.7MEDIUM
CVE-2024-45551
all versions
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification fai
6.2MEDIUM
CVE-2024-45549
all versions
Information disclosure while creating MQ channels.
7.7HIGH
CVE-2024-43065
all versions
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
7.1HIGH
CVE-2024-43046
all versions
There may be information disclosure during memory re-allocation in TZ Secure OS.
5.5MEDIUM
CVE-2024-33058
all versions
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
7.5HIGH
CVE-2025-21424
all versions
Memory corruption while calling the NPU driver APIs concurrently.
7.8HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-53024
all versions
Memory corruption in display driver while detaching a device.
7.8HIGH
CVE-2024-53014
all versions
Memory corruption may occur while validating ports and channels in Audio driver.
7.8HIGH
CVE-2024-53011
all versions
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
7.9HIGH
CVE-2024-43056
all versions
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
5.5MEDIUM
CVE-2024-43051
all versions
Information disclosure while deriving keys for a session for any Widevine use case.
5.5MEDIUM
CVE-2024-38426
all versions
While processing the authentication message in UE, improper authentication may lead to information disclosure.
5.4MEDIUM
CVE-2024-49843
all versions
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
7.8HIGH
CVE-2024-49839
all versions
Memory corruption during management frame processing due to mismatch in T2LM info element.
8.2HIGH
CVE-2024-49838
all versions
Information disclosure while parsing the OCI IE with invalid length.
8.2HIGH
CVE-2024-49834
all versions
Memory corruption while power-up or power-down sequence of the camera sensor.
7.8HIGH
CVE-2024-49833
all versions
Memory corruption can occur in the camera when an invalid CID is used.
7.8HIGH
CVE-2024-45584
all versions
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
7.8HIGH
CVE-2024-45582
all versions
Memory corruption while validating number of devices in Camera kernel .
7.8HIGH
CVE-2024-45571
all versions
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
7.8HIGH
CVE-2024-45569
all versions
Memory corruption while parsing the ML IE due to invalid frame content.
9.8CRITICAL
CVE-2024-38404
all versions
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
7.5HIGH
CVE-2024-45558
all versions
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the
7.5HIGH
CVE-2024-45553
all versions
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list whil
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin