Home/Product/qualcomm snapdragon 8 gen 1 mobile firmware
Product

qualcomm snapdragon 8 gen 1 mobile firmware

92 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-47403
all versions
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
6.5MEDIUM
CVE-2025-47401
all versions
Transient DOS when processing target power rate tables during channel configuration.
6.5MEDIUM
CVE-2025-47398
all versions
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
7.8HIGH
CVE-2025-47397
all versions
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
7.8HIGH
CVE-2025-47366
all versions
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
7.1HIGH
CVE-2025-27061
all versions
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmwar
7.8HIGH
CVE-2025-27052
all versions
Memory corruption while processing data packets in diag received from Unix clients.
7.8HIGH
CVE-2025-27043
all versions
Memory corruption while processing manipulated payload in video firmware.
7.8HIGH
CVE-2025-27042
all versions
Memory corruption while processing video packets received from video firmware.
7.8HIGH
CVE-2025-21454
all versions
Transient DOS while processing received beacon frame.
7.5HIGH
CVE-2025-21450
all versions
Cryptographic issue occurs due to use of insecure connection method while downloading.
9.1CRITICAL
CVE-2025-21449
all versions
Transient DOS may occur while processing malformed length field in SSID IEs.
7.5HIGH
CVE-2025-21446
all versions
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
7.5HIGH
CVE-2025-21433
all versions
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
6.2MEDIUM
CVE-2025-21432
all versions
Memory corruption while retrieving the CBOR data from TA.
7.8HIGH
CVE-2025-21427
all versions
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
8.2HIGH
CVE-2025-21422
all versions
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
7.1HIGH
CVE-2024-53009
all versions
Memory corruption while operating the mailbox in Automotive.
5.3MEDIUM
CVE-2025-21468
all versions
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null
7.8HIGH
CVE-2025-21467
all versions
Memory corruption while reading the FW response from the shared queue.
7.8HIGH
CVE-2025-21453
all versions
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures oc
7.8HIGH
CVE-2024-49845
all versions
Memory corruption during the FRS UDS generation process.
7.8HIGH
CVE-2024-49844
all versions
Memory corruption while triggering commands in the PlayReady Trusted application.
7.8HIGH
CVE-2024-49842
all versions
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
7.8HIGH
CVE-2024-49841
all versions
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
7.8HIGH
CVE-2024-49835
all versions
Memory corruption while reading secure file.
7.8HIGH
CVE-2024-49829
all versions
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
6.7MEDIUM
CVE-2024-45579
all versions
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due
7.8HIGH
CVE-2024-45578
all versions
Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.
7.8HIGH
CVE-2024-45577
all versions
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
7.8HIGH
CVE-2024-45576
all versions
Memory corruption while prociesing command buffer in OPE module.
7.8HIGH
CVE-2024-45575
all versions
Memory corruption Camera kernel when large number of devices are attached through userspace.
7.8HIGH
CVE-2024-45570
all versions
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
6.6MEDIUM
CVE-2024-45567
all versions
Memory corruption while encoding JPEG format.
7.8HIGH
CVE-2024-45566
all versions
Memory corruption during concurrent buffer access due to modification of the reference count.
7.8HIGH
CVE-2024-45564
all versions
Memory corruption during concurrent access to server info object due to incorrect reference count update.
7.8HIGH
CVE-2024-45563
all versions
Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding se
6.6MEDIUM
CVE-2024-45562
all versions
Memory corruption during concurrent access to server info object due to unprotected critical field.
6.6MEDIUM
CVE-2024-45554
all versions
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
7.8HIGH
CVE-2024-49838
all versions
Information disclosure while parsing the OCI IE with invalid length.
8.2HIGH
CVE-2024-49834
all versions
Memory corruption while power-up or power-down sequence of the camera sensor.
7.8HIGH
CVE-2024-49833
all versions
Memory corruption can occur in the camera when an invalid CID is used.
7.8HIGH
CVE-2024-49832
all versions
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
7.8HIGH
CVE-2024-45582
all versions
Memory corruption while validating number of devices in Camera kernel .
7.8HIGH
CVE-2024-38420
all versions
Memory corruption while configuring a Hypervisor based input virtual device.
8.8HIGH
CVE-2024-38418
all versions
Memory corruption while parsing the memory map info in IOCTL calls.
7.8HIGH
CVE-2024-38417
all versions
Information disclosure while processing IO control commands.
6.1MEDIUM
CVE-2024-38414
all versions
Information disclosure while processing information on firmware image during core initialization.
6.1MEDIUM
CVE-2024-45553
all versions
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list whil
7.8HIGH
CVE-2024-21464
all versions
Memory corruption while processing IPA statistics, when there are no active clients registered.
8.4HIGH
CVE-2024-43047
all versions
Memory corruption while maintaining memory maps of HLOS memory.
7.8HIGH
CVE-2024-38402
all versions
Memory corruption while processing IOCTL call for getting group info.
7.8HIGH
CVE-2024-33060
all versions
Memory corruption when two threads try to map and unmap a single node simultaneously.
8.4HIGH
CVE-2024-33052
all versions
Memory corruption when user provides data for FM HCI command control operations.
7.8HIGH
CVE-2024-23363
all versions
Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.
7.5HIGH
CVE-2023-43556
all versions
Memory corruption in Hypervisor when platform information mentioned is not aligned.
9.3CRITICAL
CVE-2023-43555
all versions
Information disclosure in Video while parsing mp2 clip with invalid section length.
8.2HIGH
CVE-2023-43551
all versions
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immedia
9.1CRITICAL
CVE-2023-43542
all versions
Memory corruption while copying a keyblobs material when the key materials size is not accurately checked.
7.8HIGH
CVE-2023-43538
all versions
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
9.3CRITICAL
CVE-2024-23354
all versions
Memory corruption when the IOCTL call is interrupted by a signal.
8.4HIGH
CVE-2024-23351
all versions
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
8.4HIGH
CVE-2024-21480
all versions
Memory corruption while playing audio file having large-sized input buffer.
7.3HIGH
CVE-2024-21477
all versions
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
7.5HIGH
CVE-2024-21475
all versions
Memory corruption when the payload received from firmware is not as per the expected protocol size.
7.8HIGH
CVE-2024-21471
all versions
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
8.4HIGH
CVE-2023-43531
all versions
Memory corruption while verifying the serialized header when the key pairs are generated.
8.4HIGH
CVE-2023-43530
all versions
Memory corruption in HLOS while checking for the storage type.
5.9MEDIUM
CVE-2023-43529
all versions
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
7.5HIGH
CVE-2023-43527
all versions
Information disclosure while parsing dts header atom in Video.
6.8MEDIUM
CVE-2023-43521
all versions
Memory corruption when multiple listeners are being registered with the same file descriptor.
6.7MEDIUM
CVE-2023-33119
all versions
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
8.4HIGH
CVE-2024-21472
all versions
Memory corruption in Kernel while handling GPU operations.
8.4HIGH
CVE-2024-21468
all versions
Memory corruption when there is failed unmap operation in GPU.
8.4HIGH
CVE-2024-21463
all versions
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
7.3HIGH
CVE-2023-43515
all versions
Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.
6.6MEDIUM
CVE-2023-33115
all versions
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
7.8HIGH
CVE-2023-33101
all versions
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
7.5HIGH
CVE-2023-33100
all versions
Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.
7.5HIGH
CVE-2023-33099
all versions
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
7.5HIGH
CVE-2023-33023
all versions
Memory corruption while processing finish_sign command to pass a rsp buffer.
8.4HIGH
CVE-2023-28547
all versions
Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4HIGH
CVE-2023-43550
all versions
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
7.8HIGH
CVE-2023-43549
all versions
Memory corruption while processing TPC target power table in FTM TPC.
8.4HIGH
CVE-2023-43548
all versions
Memory corruption while parsing qcp clip with invalid chunk data size.
7.3HIGH
CVE-2023-43539
all versions
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
7.5HIGH
CVE-2023-33104
all versions
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
7.5HIGH
CVE-2023-33096
all versions
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
7.5HIGH
CVE-2023-33095
all versions
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in
7.5HIGH
CVE-2023-33086
all versions
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
7.5HIGH
CVE-2023-33066
all versions
Memory corruption in Audio while processing RT proxy port register driver.
8.4HIGH
CVE-2023-28578
all versions
Memory corruption in Core Services while executing the command for removing a single event listener.
9.3CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin