Home/Product/qualcomm snapdragon 4 gen 1 firmware
Product

qualcomm snapdragon 4 gen 1 firmware

47 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-21424
all versions
Memory corruption while calling the NPU driver APIs concurrently.
7.8HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-53024
all versions
Memory corruption in display driver while detaching a device.
7.8HIGH
CVE-2024-53014
all versions
Memory corruption may occur while validating ports and channels in Audio driver.
7.8HIGH
CVE-2024-43051
all versions
Information disclosure while deriving keys for a session for any Widevine use case.
5.5MEDIUM
CVE-2024-38426
all versions
While processing the authentication message in UE, improper authentication may lead to information disclosure.
5.4MEDIUM
CVE-2024-33051
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5HIGH
CVE-2024-33050
all versions
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improp
7.5HIGH
CVE-2024-33045
all versions
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
8.4HIGH
CVE-2024-33042
all versions
Memory corruption when Alternative Frequency offset value is set to 255.
7.8HIGH
CVE-2023-33021
all versions
Memory corruption in Graphics while processing user packets for command submission.
8.4HIGH
CVE-2023-28567
all versions
Memory corruption in WLAN HAL while handling command through WMI interfaces.
7.8HIGH
CVE-2023-28565
all versions
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
7.8HIGH
CVE-2023-28564
all versions
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
7.8HIGH
CVE-2023-28538
all versions
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
8.4HIGH
CVE-2023-28542
all versions
Memory Corruption in WLAN HOST while fetching TX status information.
7.8HIGH
CVE-2023-24854
all versions
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
7.8HIGH
CVE-2023-24851
all versions
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
7.8HIGH
CVE-2023-22667
all versions
Memory Corruption in Audio while allocating the ion buffer during the music playback.
8.4HIGH
CVE-2023-22387
all versions
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
7.8HIGH
CVE-2023-22386
all versions
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
7.8HIGH
CVE-2023-21631
all versions
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from netw
7.5HIGH
CVE-2023-21629
all versions
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
6.8MEDIUM
CVE-2022-40537
all versions
Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
7.3HIGH
CVE-2022-40535
all versions
Transient DOS due to buffer over-read in WLAN while sending a packet to device.
7.5HIGH
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4HIGH
CVE-2022-40530
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
8.4HIGH
CVE-2022-40515
all versions
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
7.3HIGH
CVE-2022-33278
all versions
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer
7.8HIGH
CVE-2022-33272
all versions
Transient DOS in modem due to reachable assertion.
7.5HIGH
CVE-2022-33257
all versions
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
9.3CRITICAL
CVE-2022-33256
all versions
Memory corruption due to improper validation of array index in Multi-mode call processor.
9.8CRITICAL
CVE-2022-33254
all versions
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
7.5HIGH
CVE-2022-33250
all versions
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
7.5HIGH
CVE-2022-33244
all versions
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
7.5HIGH
CVE-2022-33242
all versions
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
7.8HIGH
CVE-2022-25709
all versions
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
8.4HIGH
CVE-2022-25705
all versions
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
7.8HIGH
CVE-2022-25694
all versions
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
8.4HIGH
CVE-2022-25655
all versions
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
8.4HIGH
CVE-2022-22075
all versions
Information Disclosure in Graphics during GPU context switch.
6.2MEDIUM
CVE-2022-40514
all versions
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc respo
9.8CRITICAL
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5HIGH
CVE-2022-33277
all versions
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
8.4HIGH
CVE-2022-33271
all versions
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
8.2HIGH
CVE-2022-33248
all versions
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
7.8HIGH
CVE-2022-33233
all versions
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin