threat
engine
.sh
Back
·
··:··
Home
/
Product
/
qualcomm snapdragon 429 mobile platform firmware
Product
qualcomm snapdragon 429 mobile platform firmware
86 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-21385
all versions
Memory corruption while using alignments for memory allocation.
7.8
HIGH
CVE-2025-47383
all versions
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
7.2
HIGH
CVE-2025-47333
all versions
Memory corruption while handling buffer mapping operations in the cryptographic driver.
6.6
MEDIUM
CVE-2025-47320
all versions
Memory corruption while processing MFC channel configuration during music playback.
7.8
HIGH
CVE-2025-27074
all versions
Memory corruption while processing a GP command response.
8.8
HIGH
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8
HIGH
CVE-2025-21488
all versions
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
8.2
HIGH
CVE-2025-21487
all versions
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than th
8.2
HIGH
CVE-2025-21484
all versions
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP pa
8.2
HIGH
CVE-2025-21483
all versions
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
9.8
CRITICAL
CVE-2025-21482
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
7.1
HIGH
CVE-2025-27071
all versions
Memory corruption while processing specific files in Powerline Communication Firmware.
7.3
HIGH
CVE-2024-53026
all versions
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
8.2
HIGH
CVE-2024-53021
all versions
Information disclosure may occur while processing goodbye RTCP packet from network.
8.2
HIGH
CVE-2024-53020
all versions
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
8.2
HIGH
CVE-2024-53019
all versions
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
8.2
HIGH
CVE-2024-53018
all versions
Memory corruption may occur while processing the OIS packet parser.
6.6
MEDIUM
CVE-2024-53017
all versions
Memory corruption while handling test pattern generator IOCTL command.
6.6
MEDIUM
CVE-2024-53016
all versions
Memory corruption while processing I2C settings in Camera driver.
6.6
MEDIUM
CVE-2024-53015
all versions
Memory corruption while processing IOCTL command to handle buffers associated with a session.
6.6
MEDIUM
CVE-2024-53013
all versions
Memory corruption may occur while processing voice call registration with user.
6.6
MEDIUM
CVE-2025-21430
all versions
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
7.5
HIGH
CVE-2025-21429
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
7.5
HIGH
CVE-2025-21428
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session
7.5
HIGH
CVE-2024-45556
all versions
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
6.5
MEDIUM
CVE-2024-45552
all versions
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to
8.2
HIGH
CVE-2024-45549
all versions
Information disclosure while creating MQ channels.
7.7
HIGH
CVE-2024-43067
all versions
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
7.8
HIGH
CVE-2024-43066
all versions
Memory corruption while handling file descriptor during listener registration/de-registration.
7.8
HIGH
CVE-2024-43065
all versions
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
7.1
HIGH
CVE-2024-43046
all versions
There may be information disclosure during memory re-allocation in TZ Secure OS.
5.5
MEDIUM
CVE-2024-43053
all versions
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
7.8
HIGH
CVE-2024-43052
all versions
Memory corruption while processing API calls to NPU with invalid input.
7.8
HIGH
CVE-2024-43050
all versions
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
7.8
HIGH
CVE-2024-43049
all versions
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
7.8
HIGH
CVE-2024-43048
all versions
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
7.8
HIGH
CVE-2024-33063
all versions
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this
7.5
HIGH
CVE-2024-33056
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
8.4
HIGH
CVE-2024-33044
all versions
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
8.4
HIGH
CVE-2024-38424
all versions
Memory corruption during GNSS HAL process initialization.
7.8
HIGH
CVE-2024-38423
all versions
Memory corruption while processing GPU page table switch.
7.8
HIGH
CVE-2024-38422
all versions
Memory corruption while processing voice packet with arbitrary data received from ADSP.
7.8
HIGH
CVE-2024-38410
all versions
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
7.8
HIGH
CVE-2024-38409
all versions
Memory corruption while station LL statistic handling.
7.8
HIGH
CVE-2024-38407
all versions
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
7.8
HIGH
CVE-2024-38406
all versions
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
7.8
HIGH
CVE-2024-38403
all versions
Transient DOS while parsing BTM ML IE when per STA profile is not included.
7.5
HIGH
CVE-2024-33068
all versions
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5
HIGH
CVE-2024-33031
all versions
Memory corruption while processing the update SIM PB records request.
6.7
MEDIUM
CVE-2024-23386
all versions
memory corruption when WiFi display APIs are invoked with large random inputs.
6.7
MEDIUM
CVE-2024-23385
all versions
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
7.5
HIGH
CVE-2024-33043
all versions
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
5.5
MEDIUM
CVE-2024-33016
all versions
memory corruption when an invalid firehose patch command is invoked.
6.8
MEDIUM
CVE-2024-23365
all versions
Memory corruption while releasing shared resources in MinkSocket listener thread.
8.4
HIGH
CVE-2024-23364
all versions
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of
7.5
HIGH
CVE-2024-23359
all versions
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
8.2
HIGH
CVE-2024-23358
all versions
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
7.5
HIGH
CVE-2024-33027
all versions
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU
8.4
HIGH
CVE-2024-23357
all versions
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
6.2
MEDIUM
CVE-2024-23353
all versions
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5
HIGH
CVE-2024-23368
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition.
7.8
HIGH
CVE-2024-21461
all versions
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4
HIGH
CVE-2023-43513
all versions
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitr
7.8
HIGH
CVE-2023-33069
all versions
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
6.7
MEDIUM
CVE-2023-33068
all versions
Memory corruption in Audio while processing IIR config data from AFE calibration block.
6.7
MEDIUM
CVE-2023-33067
all versions
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
6.7
MEDIUM
CVE-2023-33065
all versions
Information disclosure in Audio while accessing AVCS services from ADSP payload.
6.1
MEDIUM
CVE-2023-33064
all versions
Transient DOS in Audio when invoking callback function of ASM driver.
5.5
MEDIUM
CVE-2023-33120
all versions
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
7.8
HIGH
CVE-2023-33110
all versions
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP an
7.8
HIGH
CVE-2023-33033
all versions
Memory corruption in Audio during playback with speaker protection.
8.4
HIGH
CVE-2023-33030
all versions
Memory corruption in HLOS while running playready use-case.
9.3
CRITICAL
CVE-2023-33107
all versions
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
8.4
HIGH
CVE-2023-33070
all versions
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
7.1
HIGH
CVE-2023-33063
all versions
Memory corruption in DSP Services during a remote call from HLOS to DSP.
7.8
HIGH
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8
HIGH
CVE-2023-28588
all versions
Transient DOS in Bluetooth Host while rfc slot allocation.
7.5
HIGH
CVE-2023-28551
all versions
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8
HIGH
CVE-2023-28550
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8
HIGH
CVE-2023-28546
all versions
Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8
HIGH
CVE-2023-28570
all versions
Memory corruption while processing audio effects.
6.7
MEDIUM
CVE-2023-22388
all versions
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
9.8
CRITICAL
CVE-2023-24850
all versions
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
7.8
HIGH
CVE-2023-24849
all versions
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
8.2
HIGH
CVE-2023-24848
all versions
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
8.2
HIGH
CVE-2023-22385
all versions
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
8.2
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin