Home/Product/qualcomm snapdragon xr2 5g firmware
Product

qualcomm snapdragon xr2 5g firmware

97 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-47408
all versions
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
7.8HIGH
CVE-2025-47407
all versions
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
7.8HIGH
CVE-2025-47405
all versions
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
7.8HIGH
CVE-2025-47404
all versions
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
6.5MEDIUM
CVE-2025-27061
all versions
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmwar
7.8HIGH
CVE-2025-27043
all versions
Memory corruption while processing manipulated payload in video firmware.
7.8HIGH
CVE-2025-27042
all versions
Memory corruption while processing video packets received from video firmware.
7.8HIGH
CVE-2025-21454
all versions
Transient DOS while processing received beacon frame.
7.5HIGH
CVE-2025-21449
all versions
Transient DOS may occur while processing malformed length field in SSID IEs.
7.5HIGH
CVE-2025-21446
all versions
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
7.5HIGH
CVE-2025-21433
all versions
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
6.2MEDIUM
CVE-2025-21432
all versions
Memory corruption while retrieving the CBOR data from TA.
7.8HIGH
CVE-2025-21427
all versions
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
8.2HIGH
CVE-2025-21422
all versions
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
7.1HIGH
CVE-2024-53009
all versions
Memory corruption while operating the mailbox in Automotive.
5.3MEDIUM
CVE-2025-21467
all versions
Memory corruption while reading the FW response from the shared queue.
7.8HIGH
CVE-2025-21453
all versions
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures oc
7.8HIGH
CVE-2024-49845
all versions
Memory corruption during the FRS UDS generation process.
7.8HIGH
CVE-2024-49844
all versions
Memory corruption while triggering commands in the PlayReady Trusted application.
7.8HIGH
CVE-2024-49842
all versions
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
7.8HIGH
CVE-2024-49841
all versions
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
7.8HIGH
CVE-2024-49835
all versions
Memory corruption while reading secure file.
7.8HIGH
CVE-2024-45570
all versions
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
6.6MEDIUM
CVE-2024-45566
all versions
Memory corruption during concurrent buffer access due to modification of the reference count.
7.8HIGH
CVE-2024-45564
all versions
Memory corruption during concurrent access to server info object due to incorrect reference count update.
7.8HIGH
CVE-2024-45562
all versions
Memory corruption during concurrent access to server info object due to unprotected critical field.
6.6MEDIUM
CVE-2025-21424
all versions
Memory corruption while calling the NPU driver APIs concurrently.
7.8HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-53014
all versions
Memory corruption may occur while validating ports and channels in Audio driver.
7.8HIGH
CVE-2024-43057
all versions
Memory corruption while processing command in Glink linux.
7.8HIGH
CVE-2024-43056
all versions
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
5.5MEDIUM
CVE-2024-43051
all versions
Information disclosure while deriving keys for a session for any Widevine use case.
5.5MEDIUM
CVE-2024-49838
all versions
Information disclosure while parsing the OCI IE with invalid length.
8.2HIGH
CVE-2024-38420
all versions
Memory corruption while configuring a Hypervisor based input virtual device.
8.8HIGH
CVE-2024-38418
all versions
Memory corruption while parsing the memory map info in IOCTL calls.
7.8HIGH
CVE-2024-33067
all versions
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound
6.1MEDIUM
CVE-2024-43047
all versions
Memory corruption while maintaining memory maps of HLOS memory.
7.8HIGH
CVE-2024-33060
all versions
Memory corruption when two threads try to map and unmap a single node simultaneously.
8.4HIGH
CVE-2024-33052
all versions
Memory corruption when user provides data for FM HCI command control operations.
7.8HIGH
CVE-2024-33051
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5HIGH
CVE-2024-33042
all versions
Memory corruption when Alternative Frequency offset value is set to 255.
7.8HIGH
CVE-2023-43555
all versions
Information disclosure in Video while parsing mp2 clip with invalid section length.
8.2HIGH
CVE-2023-43551
all versions
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immedia
9.1CRITICAL
CVE-2023-43542
all versions
Memory corruption while copying a keyblobs material when the key materials size is not accurately checked.
7.8HIGH
CVE-2023-43538
all versions
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
9.3CRITICAL
CVE-2024-21480
all versions
Memory corruption while playing audio file having large-sized input buffer.
7.3HIGH
CVE-2024-21476
all versions
Memory corruption when the channel ID passed by user is not validated and further used.
7.8HIGH
CVE-2024-21475
all versions
Memory corruption when the payload received from firmware is not as per the expected protocol size.
7.8HIGH
CVE-2024-21471
all versions
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
8.4HIGH
CVE-2023-43531
all versions
Memory corruption while verifying the serialized header when the key pairs are generated.
8.4HIGH
CVE-2023-43530
all versions
Memory corruption in HLOS while checking for the storage type.
5.9MEDIUM
CVE-2023-43529
all versions
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
7.5HIGH
CVE-2023-43528
all versions
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than
6.1MEDIUM
CVE-2023-43527
all versions
Information disclosure while parsing dts header atom in Video.
6.8MEDIUM
CVE-2023-43521
all versions
Memory corruption when multiple listeners are being registered with the same file descriptor.
6.7MEDIUM
CVE-2023-33119
all versions
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
8.4HIGH
CVE-2024-21468
all versions
Memory corruption when there is failed unmap operation in GPU.
8.4HIGH
CVE-2024-21463
all versions
Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
7.3HIGH
CVE-2023-33115
all versions
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
7.8HIGH
CVE-2023-33111
all versions
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibra
5.5MEDIUM
CVE-2023-33101
all versions
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
7.5HIGH
CVE-2023-33099
all versions
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
7.5HIGH
CVE-2023-33023
all versions
Memory corruption while processing finish_sign command to pass a rsp buffer.
8.4HIGH
CVE-2023-28547
all versions
Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4HIGH
CVE-2023-43549
all versions
Memory corruption while processing TPC target power table in FTM TPC.
8.4HIGH
CVE-2023-43548
all versions
Memory corruption while parsing qcp clip with invalid chunk data size.
7.3HIGH
CVE-2023-43539
all versions
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
7.5HIGH
CVE-2023-33104
all versions
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
7.5HIGH
CVE-2023-33096
all versions
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
7.5HIGH
CVE-2023-33095
all versions
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in
7.5HIGH
CVE-2023-33090
all versions
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
5.5MEDIUM
CVE-2023-33086
all versions
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
7.5HIGH
CVE-2023-33066
all versions
Memory corruption in Audio while processing RT proxy port register driver.
8.4HIGH
CVE-2023-28578
all versions
Memory corruption in Core Services while executing the command for removing a single event listener.
9.3CRITICAL
CVE-2023-33021
all versions
Memory corruption in Graphics while processing user packets for command submission.
8.4HIGH
CVE-2023-33015
all versions
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
7.5HIGH
CVE-2023-28581
all versions
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
9.8CRITICAL
CVE-2023-28573
all versions
Memory corruption in WLAN HAL while parsing WMI command parameters.
7.8HIGH
CVE-2023-28567
all versions
Memory corruption in WLAN HAL while handling command through WMI interfaces.
7.8HIGH
CVE-2023-28577
all versions
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called c
6.7MEDIUM
CVE-2023-28576
all versions
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it.
6.4MEDIUM
CVE-2023-28575
all versions
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invali
6.7MEDIUM
CVE-2023-28542
all versions
Memory Corruption in WLAN HOST while fetching TX status information.
7.8HIGH
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8HIGH
CVE-2023-24854
all versions
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
7.8HIGH
CVE-2023-24851
all versions
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
7.8HIGH
CVE-2023-22667
all versions
Memory Corruption in Audio while allocating the ion buffer during the music playback.
8.4HIGH
CVE-2023-22387
all versions
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
7.8HIGH
CVE-2023-22386
all versions
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
7.8HIGH
CVE-2023-21672
all versions
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
8.4HIGH
CVE-2023-21638
all versions
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
6.7MEDIUM
CVE-2023-21637
all versions
Memory corruption in Linux while calling system configuration APIs.
6.7MEDIUM
CVE-2023-21635
all versions
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
6.7MEDIUM
CVE-2023-21633
all versions
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
6.7MEDIUM
CVE-2023-21631
all versions
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from netw
7.5HIGH
CVE-2023-21629
all versions
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
6.8MEDIUM
CVE-2023-21624
all versions
Information disclosure in DSP Services while loading dynamic module.
6.2MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin