Home/Product/qualcomm snapdragon 425 mobile platform firmware
Product

qualcomm snapdragon 425 mobile platform firmware

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8HIGH
CVE-2025-21487
all versions
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than th
8.2HIGH
CVE-2025-21483
all versions
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
9.8CRITICAL
CVE-2025-21482
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
7.1HIGH
CVE-2024-53026
all versions
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
8.2HIGH
CVE-2024-53021
all versions
Information disclosure may occur while processing goodbye RTCP packet from network.
8.2HIGH
CVE-2024-53020
all versions
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
8.2HIGH
CVE-2025-21428
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session
7.5HIGH
CVE-2024-43052
all versions
Memory corruption while processing API calls to NPU with invalid input.
7.8HIGH
CVE-2024-38423
all versions
Memory corruption while processing GPU page table switch.
7.8HIGH
CVE-2024-38422
all versions
Memory corruption while processing voice packet with arbitrary data received from ADSP.
7.8HIGH
CVE-2024-23385
all versions
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
7.5HIGH
CVE-2024-33043
all versions
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
5.5MEDIUM
CVE-2024-23359
all versions
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
8.2HIGH
CVE-2024-23358
all versions
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
7.5HIGH
CVE-2024-23357
all versions
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
6.2MEDIUM
CVE-2024-23353
all versions
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5HIGH
CVE-2024-21461
all versions
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4HIGH
CVE-2023-43513
all versions
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitr
7.8HIGH
CVE-2023-33110
all versions
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP an
7.8HIGH
CVE-2023-33033
all versions
Memory corruption in Audio during playback with speaker protection.
8.4HIGH
CVE-2023-33030
all versions
Memory corruption in HLOS while running playready use-case.
9.3CRITICAL
CVE-2023-33107
all versions
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
8.4HIGH
CVE-2023-33063
all versions
Memory corruption in DSP Services during a remote call from HLOS to DSP.
7.8HIGH
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8HIGH
CVE-2023-28588
all versions
Transient DOS in Bluetooth Host while rfc slot allocation.
7.5HIGH
CVE-2023-28551
all versions
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8HIGH
CVE-2023-28550
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8HIGH
CVE-2023-28546
all versions
Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8HIGH
CVE-2023-33059
all versions
Memory corruption in Audio while processing the VOC packet data from ADSP.
7.8HIGH
CVE-2023-22388
all versions
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
9.8CRITICAL
CVE-2023-24850
all versions
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
7.8HIGH
CVE-2023-24849
all versions
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
8.2HIGH
CVE-2023-24848
all versions
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
8.2HIGH
CVE-2023-22385
all versions
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
8.2HIGH
CVE-2022-40521
all versions
Transient DOS due to improper authorization in Modem
7.5HIGH
CVE-2022-33264
all versions
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
7.9HIGH
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin