Home/Product/qualcomm sxr2130 firmware
Product

qualcomm sxr2130 firmware

498 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-27070
all versions
Memory corruption while performing encryption and decryption commands.
7.8HIGH
CVE-2025-27054
all versions
Memory corruption while processing a malformed license file during reboot.
7.8HIGH
CVE-2025-27053
all versions
Memory corruption during PlayReady APP usecase while processing TA commands.
7.8HIGH
CVE-2025-27037
all versions
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
7.8HIGH
CVE-2025-27032
all versions
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
7.8HIGH
CVE-2025-21487
all versions
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than th
8.2HIGH
CVE-2025-21484
all versions
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP pa
8.2HIGH
CVE-2025-21483
all versions
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
9.8CRITICAL
CVE-2025-21482
all versions
Cryptographic issue while performing RSA PKCS padding decoding.
7.1HIGH
CVE-2025-21481
all versions
Memory corruption while performing private key encryption in trusted application.
7.8HIGH
CVE-2025-27071
all versions
Memory corruption while processing specific files in Powerline Communication Firmware.
7.3HIGH
CVE-2025-27066
all versions
Transient DOS while processing an ANQP message.
7.5HIGH
CVE-2025-21474
all versions
Memory corruption while processing commands from A2dp sink command queue.
7.8HIGH
CVE-2025-21465
all versions
Information disclosure while processing the hash segment in an MBN file.
6.5MEDIUM
CVE-2025-21464
all versions
Information disclosure while reading data from an image using specified offset and size parameters.
6.5MEDIUM
CVE-2025-21455
all versions
Memory corruption while submitting blob data to kernel space though IOCTL.
7.8HIGH
CVE-2025-21452
all versions
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
7.5HIGH
CVE-2025-27061
all versions
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmwar
7.8HIGH
CVE-2025-27042
all versions
Memory corruption while processing video packets received from video firmware.
7.8HIGH
CVE-2025-21454
all versions
Transient DOS while processing received beacon frame.
7.5HIGH
CVE-2025-21449
all versions
Transient DOS may occur while processing malformed length field in SSID IEs.
7.5HIGH
CVE-2025-21446
all versions
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
7.5HIGH
CVE-2025-21433
all versions
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
6.2MEDIUM
CVE-2025-21432
all versions
Memory corruption while retrieving the CBOR data from TA.
7.8HIGH
CVE-2025-21427
all versions
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
8.2HIGH
CVE-2025-21422
all versions
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
7.1HIGH
CVE-2024-53009
all versions
Memory corruption while operating the mailbox in Automotive.
5.3MEDIUM
CVE-2024-53026
all versions
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
8.2HIGH
CVE-2024-53021
all versions
Information disclosure may occur while processing goodbye RTCP packet from network.
8.2HIGH
CVE-2024-53020
all versions
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
8.2HIGH
CVE-2024-53016
all versions
Memory corruption while processing I2C settings in Camera driver.
6.6MEDIUM
CVE-2024-53013
all versions
Memory corruption may occur while processing voice call registration with user.
6.6MEDIUM
CVE-2024-53010
all versions
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
7.8HIGH
CVE-2025-21453
all versions
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures oc
7.8HIGH
CVE-2024-49845
all versions
Memory corruption during the FRS UDS generation process.
7.8HIGH
CVE-2024-49844
all versions
Memory corruption while triggering commands in the PlayReady Trusted application.
7.8HIGH
CVE-2024-49842
all versions
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
7.8HIGH
CVE-2024-49841
all versions
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
7.8HIGH
CVE-2024-49835
all versions
Memory corruption while reading secure file.
7.8HIGH
CVE-2024-45570
all versions
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
6.6MEDIUM
CVE-2024-45566
all versions
Memory corruption during concurrent buffer access due to modification of the reference count.
7.8HIGH
CVE-2024-45564
all versions
Memory corruption during concurrent access to server info object due to incorrect reference count update.
7.8HIGH
CVE-2024-45562
all versions
Memory corruption during concurrent access to server info object due to unprotected critical field.
6.6MEDIUM
CVE-2025-21448
all versions
Transient DOS may occur while parsing SSID in action frames.
7.5HIGH
CVE-2025-21430
all versions
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
7.5HIGH
CVE-2025-21429
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
7.5HIGH
CVE-2024-45552
all versions
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to
8.2HIGH
CVE-2024-45551
all versions
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification fai
6.2MEDIUM
CVE-2024-45549
all versions
Information disclosure while creating MQ channels.
7.7HIGH
CVE-2024-45544
all versions
Memory corruption while processing IOCTL calls to add route entry in the HW.
6.6MEDIUM
CVE-2024-45543
all versions
Memory corruption while accessing MSM channel map and mixer functions.
6.6MEDIUM
CVE-2024-45540
all versions
Memory corruption while invoking IOCTL map buffer request from userspace.
6.6MEDIUM
CVE-2024-43067
all versions
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
7.8HIGH
CVE-2024-43066
all versions
Memory corruption while handling file descriptor during listener registration/de-registration.
7.8HIGH
CVE-2024-43065
all versions
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
7.1HIGH
CVE-2024-43046
all versions
There may be information disclosure during memory re-allocation in TZ Secure OS.
5.5MEDIUM
CVE-2024-33058
all versions
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
7.5HIGH
CVE-2025-21424
all versions
Memory corruption while calling the NPU driver APIs concurrently.
7.8HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-53014
all versions
Memory corruption may occur while validating ports and channels in Audio driver.
7.8HIGH
CVE-2024-43057
all versions
Memory corruption while processing command in Glink linux.
7.8HIGH
CVE-2024-43056
all versions
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
5.5MEDIUM
CVE-2024-43051
all versions
Information disclosure while deriving keys for a session for any Widevine use case.
5.5MEDIUM
CVE-2024-49838
all versions
Information disclosure while parsing the OCI IE with invalid length.
8.2HIGH
CVE-2024-38420
all versions
Memory corruption while configuring a Hypervisor based input virtual device.
8.8HIGH
CVE-2024-38418
all versions
Memory corruption while parsing the memory map info in IOCTL calls.
7.8HIGH
CVE-2024-38416
all versions
Information disclosure during audio playback.
6.1MEDIUM
CVE-2024-33067
all versions
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound
6.1MEDIUM
CVE-2024-43052
all versions
Memory corruption while processing API calls to NPU with invalid input.
7.8HIGH
CVE-2024-33056
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
8.4HIGH
CVE-2024-33053
all versions
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
6.7MEDIUM
CVE-2024-33044
all versions
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
8.4HIGH
CVE-2024-33040
all versions
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in ke
6.7MEDIUM
CVE-2024-33037
all versions
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message r
6.1MEDIUM
CVE-2024-33036
all versions
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and
6.7MEDIUM
CVE-2024-38423
all versions
Memory corruption while processing GPU page table switch.
7.8HIGH
CVE-2024-38422
all versions
Memory corruption while processing voice packet with arbitrary data received from ADSP.
7.8HIGH
CVE-2024-38415
all versions
Memory corruption while handling session errors from firmware.
7.8HIGH
CVE-2024-38408
all versions
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
8.2HIGH
CVE-2024-33032
all versions
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
6.7MEDIUM
CVE-2024-43047
all versions
Memory corruption while maintaining memory maps of HLOS memory.
7.8HIGH
CVE-2024-23369
all versions
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
7.8HIGH
CVE-2024-33060
all versions
Memory corruption when two threads try to map and unmap a single node simultaneously.
8.4HIGH
CVE-2024-33052
all versions
Memory corruption when user provides data for FM HCI command control operations.
7.8HIGH
CVE-2024-33051
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5HIGH
CVE-2024-33043
all versions
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
5.5MEDIUM
CVE-2024-33042
all versions
Memory corruption when Alternative Frequency offset value is set to 255.
7.8HIGH
CVE-2024-33035
all versions
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
8.4HIGH
CVE-2024-33016
all versions
memory corruption when an invalid firehose patch command is invoked.
6.8MEDIUM
CVE-2024-23364
all versions
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of
7.5HIGH
CVE-2024-23362
all versions
Cryptographic issue while parsing RSA keys in COBR format.
7.1HIGH
CVE-2024-23359
all versions
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
8.2HIGH
CVE-2024-33025
all versions
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
7.5HIGH
CVE-2024-33024
all versions
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE lengt
7.5HIGH
CVE-2024-33020
all versions
Transient DOS while processing TID-to-link mapping IE elements.
7.5HIGH
CVE-2024-33014
all versions
Transient DOS while parsing ESP IE from beacon/probe response frame.
7.5HIGH
CVE-2024-23357
all versions
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
6.2MEDIUM
CVE-2024-23356
all versions
Memory corruption during session sign renewal request calls in HLOS.
7.8HIGH
CVE-2024-23355
all versions
Memory corruption when keymaster operation imports a shared key.
7.8HIGH
CVE-2024-23353
all versions
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
7.5HIGH
CVE-2024-23352
all versions
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
7.5HIGH
CVE-2024-21481
all versions
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
8.4HIGH
CVE-2024-21479
all versions
Transient DOS during music playback of ALAC content.
7.5HIGH
CVE-2024-21459
all versions
Information disclosure while handling beacon or probe response frame in STA.
6.5MEDIUM
CVE-2024-23373
all versions
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
8.4HIGH
CVE-2024-23368
all versions
Memory corruption when allocating and accessing an entry in an SMEM partition.
7.8HIGH
CVE-2024-21469
all versions
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
7.3HIGH
CVE-2024-21465
all versions
Memory corruption while processing key blob passed by the user.
7.8HIGH
CVE-2024-21462
all versions
Transient DOS while loading the TA ELF file.
7.1HIGH
CVE-2024-21461
all versions
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
8.4HIGH
CVE-2023-43555
all versions
Information disclosure in Video while parsing mp2 clip with invalid section length.
8.2HIGH
CVE-2023-43551
all versions
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immedia
9.1CRITICAL
CVE-2023-43542
all versions
Memory corruption while copying a keyblobs material when the key materials size is not accurately checked.
7.8HIGH
CVE-2023-43538
all versions
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
9.3CRITICAL
CVE-2024-21476
all versions
Memory corruption when the channel ID passed by user is not validated and further used.
7.8HIGH
CVE-2024-21475
all versions
Memory corruption when the payload received from firmware is not as per the expected protocol size.
7.8HIGH
CVE-2023-43531
all versions
Memory corruption while verifying the serialized header when the key pairs are generated.
8.4HIGH
CVE-2023-43530
all versions
Memory corruption in HLOS while checking for the storage type.
5.9MEDIUM
CVE-2023-43529
all versions
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
7.5HIGH
CVE-2023-43528
all versions
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than
6.1MEDIUM
CVE-2023-43527
all versions
Information disclosure while parsing dts header atom in Video.
6.8MEDIUM
CVE-2023-43524
all versions
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
6.7MEDIUM
CVE-2023-43521
all versions
Memory corruption when multiple listeners are being registered with the same file descriptor.
6.7MEDIUM
CVE-2023-33119
all versions
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
8.4HIGH
CVE-2024-21468
all versions
Memory corruption when there is failed unmap operation in GPU.
8.4HIGH
CVE-2023-33115
all versions
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
7.8HIGH
CVE-2023-33111
all versions
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibra
5.5MEDIUM
CVE-2023-33101
all versions
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
7.5HIGH
CVE-2023-33099
all versions
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
7.5HIGH
CVE-2023-33023
all versions
Memory corruption while processing finish_sign command to pass a rsp buffer.
8.4HIGH
CVE-2023-28547
all versions
Memory corruption in SPS Application while requesting for public key in sorter TA.
8.4HIGH
CVE-2023-33104
all versions
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
7.5HIGH
CVE-2023-33096
all versions
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
7.5HIGH
CVE-2023-33095
all versions
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in
7.5HIGH
CVE-2023-33090
all versions
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
5.5MEDIUM
CVE-2023-33086
all versions
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
7.5HIGH
CVE-2023-33066
all versions
Memory corruption in Audio while processing RT proxy port register driver.
8.4HIGH
CVE-2023-28578
all versions
Memory corruption in Core Services while executing the command for removing a single event listener.
9.3CRITICAL
CVE-2023-43536
all versions
Transient DOS while parse fils IE with length equal to 1.
7.5HIGH
CVE-2023-43533
all versions
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
7.5HIGH
CVE-2023-43523
all versions
Transient DOS while processing 11AZ RTT management action frame received through OTA.
7.5HIGH
CVE-2023-43522
all versions
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
7.5HIGH
CVE-2023-43513
all versions
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitr
7.8HIGH
CVE-2023-33077
all versions
Memory corruption in HLOS while converting from authorization token to HIDL vector.
6.7MEDIUM
CVE-2023-33076
all versions
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
5.9MEDIUM
CVE-2023-33072
all versions
Memory corruption in Core while processing control functions.
9.3CRITICAL
CVE-2023-33069
all versions
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
6.7MEDIUM
CVE-2023-33068
all versions
Memory corruption in Audio while processing IIR config data from AFE calibration block.
6.7MEDIUM
CVE-2023-33067
all versions
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
6.7MEDIUM
CVE-2023-33065
all versions
Information disclosure in Audio while accessing AVCS services from ADSP payload.
6.1MEDIUM
CVE-2023-33064
all versions
Transient DOS in Audio when invoking callback function of ASM driver.
5.5MEDIUM
CVE-2023-33057
all versions
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
7.5HIGH
CVE-2023-33049
all versions
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
7.5HIGH
CVE-2023-43511
all versions
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTO_NONE as the n
7.5HIGH
CVE-2023-33120
all versions
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
7.8HIGH
CVE-2023-33117
all versions
Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MOD
7.8HIGH
CVE-2023-33114
all versions
Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the
8.4HIGH
CVE-2023-33110
all versions
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP an
7.8HIGH
CVE-2023-33109
all versions
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
7.5HIGH
CVE-2023-33094
all versions
Memory corruption while running VK synchronization with KASAN enabled.
8.4HIGH
CVE-2023-33062
all versions
Transient DOS in WLAN Firmware while parsing a BTM request.
7.5HIGH
CVE-2023-33040
all versions
Transient DOS in Data Modem during DTLS handshake.
7.5HIGH
CVE-2023-33038
all versions
Memory corruption while receiving a message in Bus Socket Transport Server.
6.7MEDIUM
CVE-2023-33037
all versions
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
7.1HIGH
CVE-2023-33036
all versions
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
7.1HIGH
CVE-2023-33033
all versions
Memory corruption in Audio during playback with speaker protection.
8.4HIGH
CVE-2023-33030
all versions
Memory corruption in HLOS while running playready use-case.
9.3CRITICAL
CVE-2023-33107
all versions
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
8.4HIGH
CVE-2023-33106
all versions
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
8.4HIGH
CVE-2023-33098
all versions
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
7.5HIGH
CVE-2023-33089
all versions
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
7.5HIGH
CVE-2023-33088
all versions
Memory corruption when processing cmd parameters while parsing vdev.
8.4HIGH
CVE-2023-33081
all versions
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
7.5HIGH
CVE-2023-33080
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5HIGH
CVE-2023-33079
all versions
Memory corruption in Audio while running invalid audio recording from ADSP.
7.8HIGH
CVE-2023-33063
all versions
Memory corruption in DSP Services during a remote call from HLOS to DSP.
7.8HIGH
CVE-2023-33054
all versions
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
9.1CRITICAL
CVE-2023-33044
all versions
Transient DOS in Data modem while handling TLB control messages from the Network.
7.5HIGH
CVE-2023-33042
all versions
Transient DOS in Modem after RRC Setup message is received.
7.5HIGH
CVE-2023-33024
all versions
Memory corruption while sending SMS from AP firmware.
6.7MEDIUM
CVE-2023-33022
all versions
Memory corruption in HLOS while invoking IOCTL calls from user-space.
8.4HIGH
CVE-2023-33018
all versions
Memory corruption while using the UIM diag command to get the operators name.
7.8HIGH
CVE-2023-33017
all versions
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
7.8HIGH
CVE-2023-28588
all versions
Transient DOS in Bluetooth Host while rfc slot allocation.
7.5HIGH
CVE-2023-28587
all versions
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
7.8HIGH
CVE-2023-28586
all versions
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
6.0MEDIUM
CVE-2023-28585
all versions
Memory corruption while loading an ELF segment in TEE Kernel.
8.2HIGH
CVE-2023-28551
all versions
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
7.8HIGH
CVE-2023-28550
all versions
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
7.8HIGH
CVE-2023-28546
all versions
Memory Corruption in SPS Application while exporting public key in sorter TA.
7.8HIGH
CVE-2023-22668
all versions
Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
6.7MEDIUM
CVE-2023-22383
all versions
Memory Corruption in camera while installing a fd for a particular DMA buffer.
6.7MEDIUM
CVE-2023-21634
all versions
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
6.7MEDIUM
CVE-2023-33059
all versions
Memory corruption in Audio while processing the VOC packet data from ADSP.
7.8HIGH
CVE-2023-33055
all versions
Memory Corruption in Audio while invoking callback function in driver from ADSP.
7.8HIGH
CVE-2023-33047
all versions
Transient DOS in WLAN Firmware while parsing no-inherit IES.
7.5HIGH
CVE-2023-33031
all versions
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
7.8HIGH
CVE-2023-28570
all versions
Memory corruption while processing audio effects.
6.7MEDIUM
CVE-2023-28556
all versions
Cryptographic issue in HLOS during key management.
7.1HIGH
CVE-2023-28554
all versions
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
6.1MEDIUM
CVE-2023-28553
all versions
Information Disclosure in WLAN Host when processing WMI event command.
6.1MEDIUM
CVE-2023-28545
all versions
Memory corruption in TZ Secure OS while loading an app ELF.
8.2HIGH
CVE-2023-24852
all versions
Memory Corruption in Core due to secure memory access by user while loading modem image.
8.4HIGH
CVE-2023-22388
all versions
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
9.8CRITICAL
CVE-2023-33035
all versions
Memory corruption while invoking callback function of AFE from ADSP.
7.8HIGH
CVE-2023-33028
all versions
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
9.8CRITICAL
CVE-2023-33027
all versions
Transient DOS in WLAN Firmware while parsing rsn ies.
7.5HIGH
CVE-2023-33026
all versions
Transient DOS in WLAN Firmware while parsing a NAN management frame.
7.5HIGH
CVE-2023-28571
all versions
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
6.1MEDIUM
CVE-2023-28540
all versions
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
9.1CRITICAL
CVE-2023-28539
all versions
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
6.6MEDIUM
CVE-2023-24853
all versions
Memory Corruption in HLOS while registering for key provisioning notify.
8.4HIGH
CVE-2023-24850
all versions
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
7.8HIGH
CVE-2023-24849
all versions
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
8.2HIGH
CVE-2023-24848
all versions
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
8.2HIGH
CVE-2023-24847
all versions
Transient DOS in Modem while allocating DSM items.
7.5HIGH
CVE-2023-24843
all versions
Transient DOS in Modem while triggering a camping on an 5G cell.
7.5HIGH
CVE-2023-22385
all versions
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
8.2HIGH
CVE-2023-21673
all versions
Improper Access to the VM resource manager can lead to Memory Corruption.
8.7HIGH
CVE-2023-33021
all versions
Memory corruption in Graphics while processing user packets for command submission.
8.4HIGH
CVE-2023-33015
all versions
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
7.5HIGH
CVE-2023-28573
all versions
Memory corruption in WLAN HAL while parsing WMI command parameters.
7.8HIGH
CVE-2023-28567
all versions
Memory corruption in WLAN HAL while handling command through WMI interfaces.
7.8HIGH
CVE-2023-28558
all versions
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
7.8HIGH
CVE-2023-28557
all versions
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
7.8HIGH
CVE-2023-28549
all versions
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
7.8HIGH
CVE-2023-28548
all versions
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
7.8HIGH
CVE-2023-28538
all versions
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
8.4HIGH
CVE-2022-33275
all versions
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
8.4HIGH
CVE-2023-28577
all versions
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called c
6.7MEDIUM
CVE-2023-28576
all versions
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it.
6.4MEDIUM
CVE-2023-28575
all versions
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invali
6.7MEDIUM
CVE-2023-28537
all versions
Memory corruption while allocating memory in COmxApeDec module in Audio.
8.4HIGH
CVE-2023-28542
all versions
Memory Corruption in WLAN HOST while fetching TX status information.
7.8HIGH
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8HIGH
CVE-2023-22667
all versions
Memory Corruption in Audio while allocating the ion buffer during the music playback.
8.4HIGH
CVE-2023-22387
all versions
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
7.8HIGH
CVE-2023-22386
all versions
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
7.8HIGH
CVE-2023-21638
all versions
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
6.7MEDIUM
CVE-2023-21637
all versions
Memory corruption in Linux while calling system configuration APIs.
6.7MEDIUM
CVE-2023-21635
all versions
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
6.7MEDIUM
CVE-2023-21633
all versions
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
6.7MEDIUM
CVE-2023-21631
all versions
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from netw
7.5HIGH
CVE-2023-21629
all versions
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
6.8MEDIUM
CVE-2023-21624
all versions
Information disclosure in DSP Services while loading dynamic module.
6.2MEDIUM
CVE-2023-21670
all versions
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
7.8HIGH
CVE-2023-21669
all versions
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
8.2HIGH
CVE-2023-21659
all versions
Transient DOS in WLAN Firmware while processing frames with missing header fields.
7.5HIGH
CVE-2023-21658
all versions
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
7.5HIGH
CVE-2023-21657
all versions
Memoru corruption in Audio when ADSP sends input during record use case.
7.8HIGH
CVE-2023-21656
all versions
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
7.8HIGH
CVE-2022-40536
all versions
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
7.5HIGH
CVE-2022-40533
all versions
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
6.2MEDIUM
CVE-2022-40529
all versions
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
7.1HIGH
CVE-2022-40523
all versions
Information disclosure in Kernel due to indirect branch misprediction.
7.1HIGH
CVE-2022-40521
all versions
Transient DOS due to improper authorization in Modem
7.5HIGH
CVE-2022-40507
all versions
Memory corruption due to double free in Core while mapping HLOS address to the list.
8.4HIGH
CVE-2022-33307
all versions
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
8.4HIGH
CVE-2022-33267
all versions
Memory corruption in Linux while sending DRM request.
6.7MEDIUM
CVE-2022-33264
all versions
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
7.9HIGH
CVE-2022-33251
all versions
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
7.5HIGH
CVE-2022-33227
all versions
Memory corruption in Linux android due to double free while calling unregister provider after register call.
6.7MEDIUM
CVE-2022-22076
all versions
information disclosure due to cryptographic issue in Core during RPMB read request.
7.1HIGH
CVE-2022-22060
all versions
Assertion occurs while processing Reconfiguration message due to improper validation
7.5HIGH
CVE-2022-40504
all versions
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
7.5HIGH
CVE-2022-33273
all versions
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
7.3HIGH
CVE-2023-21666
all versions
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
8.4HIGH
CVE-2023-21665
all versions
Memory corruption in Graphics while importing a file.
8.4HIGH
CVE-2022-40508
all versions
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not suppor
7.5HIGH
CVE-2022-25713
all versions
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a s
7.8HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4HIGH
CVE-2022-40503
all versions
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
8.2HIGH
CVE-2022-33302
all versions
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command le
6.8MEDIUM
CVE-2022-33298
all versions
Memory corruption due to use after free in Modem while modem initialization.
6.7MEDIUM
CVE-2022-33296
all versions
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
5.9MEDIUM
CVE-2022-33289
all versions
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
6.8MEDIUM
CVE-2022-33288
all versions
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection
9.3CRITICAL
CVE-2022-33269
all versions
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
9.3CRITICAL
CVE-2022-33231
all versions
Memory corruption due to double free in core while initializing the encryption key.
9.3CRITICAL
CVE-2021-30327
all versions
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile,
7.5HIGH
CVE-2020-3632
all versions
u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mob
7.8HIGH
CVE-2020-11207
all versions
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Com
7.8HIGH
CVE-2020-11206
all versions
Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdrago
7.8HIGH
CVE-2020-11205
all versions
u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdrago
7.8HIGH
CVE-2020-11196
all versions
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon A
9.8CRITICAL
CVE-2020-11193
all versions
u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Aut
9.8CRITICAL
CVE-2020-11184
all versions
u'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, Snapdragon
9.8CRITICAL
CVE-2020-11175
all versions
u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due
7.8HIGH
CVE-2020-11168
all versions
u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range'
9.8CRITICAL
CVE-2020-11132
all versions
u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, S
7.1HIGH
CVE-2020-11130
all versions
u'Possible buffer overflow in WIFI hal process due to copying data without checking the buffer length' in Snapdragon Auto, Snapdra
7.8HIGH
CVE-2020-11127
all versions
u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validati
7.8HIGH
CVE-2020-11123
all versions
u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at get
5.5MEDIUM
CVE-2020-11121
all versions
u'Possible buffer overflow in WIFI hal process due to usage of memcpy without checking length of destination buffer' in Snapdragon
7.8HIGH
CVE-2020-3704
all versions
u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device may lead per
7.5HIGH
CVE-2020-3694
all versions
u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto
7.8HIGH
CVE-2020-3693
all versions
u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snapdragon Aut
7.8HIGH
CVE-2020-3692
all versions
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for
9.8CRITICAL
CVE-2020-3690
all versions
u'Due to an incorrect SMMU configuration, the modem crypto engine can potentially compromise the hypervisor' in Snapdragon Auto, S
7.8HIGH
CVE-2020-3684
all versions
u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader and applie
7.8HIGH
CVE-2020-3673
all versions
u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to valida
9.8CRITICAL
CVE-2020-3654
all versions
u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in S
9.8CRITICAL
CVE-2020-3638
all versions
u'An Unaligned address or size can propagate to the database due to improper page permissions and can lead to improper access cont
7.8HIGH
CVE-2020-11174
all versions
u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdragon Auto,
7.8HIGH
CVE-2020-11173
all versions
u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon
7.0HIGH
CVE-2020-11164
all versions
u'Third-party app may also call the broadcasts in Perfdump and cause privilege escalation issue due to improper access control' in
7.8HIGH
CVE-2020-11162
all versions
u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI device side' in
7.8HIGH
CVE-2020-11125
all versions
u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devices' in Sna
7.8HIGH
CVE-2020-3679
all versions
u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address i
5.5MEDIUM
CVE-2020-3674
all versions
Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdragon Compu
5.5MEDIUM
CVE-2020-3656
all versions
Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI devices i
7.8HIGH
CVE-2020-11135
all versions
u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapd
7.5HIGH
CVE-2020-11129
all versions
u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail due to mem
7.8HIGH
CVE-2020-11124
all versions
u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.'
7.8HIGH
CVE-2020-3646
all versions
u'Buffer overflow seen as the destination buffer size is lesser than the source buffer size in video application' in Snapdragon Co
7.8HIGH
CVE-2020-3644
all versions
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in
5.5MEDIUM
CVE-2020-3643
all versions
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snapdragon Com
5.5MEDIUM
CVE-2020-3640
all versions
u'Resizing the usage table header before passing all the checks leads to the function exiting with a usage table in invalid state
7.8HIGH
CVE-2020-3636
all versions
u'Out of bound writes happen when accessing usage_table header entry beyond the memory allocated for the header' in Snapdragon Aut
7.8HIGH
CVE-2020-3629
all versions
u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining the buffer
7.8HIGH
CVE-2020-3622
all versions
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated fo
7.8HIGH
CVE-2020-3621
all versions
u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size res
5.5MEDIUM
CVE-2020-3620
all versions
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport ca
5.5MEDIUM
CVE-2020-11128
all versions
u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in Snapdragon
7.8HIGH
CVE-2020-11122
all versions
u'Null Pointer exception while playing crafted mkv file as data stream get deleted on secondary invalid configuration' in Snapdrag
5.5MEDIUM
CVE-2020-11120
all versions
u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback,
7.8HIGH
CVE-2020-11118
all versions
u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2020-11116
all versions
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapd
9.8CRITICAL
CVE-2020-11115
all versions
u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in S
7.5HIGH
CVE-2019-14119
all versions
u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to
7.0HIGH
CVE-2019-14117
all versions
u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list wh
7.8HIGH
CVE-2019-14115
all versions
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which c
5.5MEDIUM
CVE-2019-14089
all versions
u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned af
7.8HIGH
CVE-2019-14074
all versions
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon C
7.8HIGH
CVE-2019-14065
all versions
u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2019-14056
all versions
u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snap
7.8HIGH
CVE-2019-14025
all versions
u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to refer to
5.5MEDIUM
CVE-2019-13999
all versions
u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information
7.8HIGH
CVE-2019-13998
all versions
u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into mem
7.8HIGH
CVE-2019-13995
all versions
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to mem
7.8HIGH
CVE-2019-13994
all versions
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than
7.8HIGH
CVE-2019-13992
all versions
u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in Snapdragon
7.8HIGH
CVE-2019-10629
all versions
u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdragon Comput
7.8HIGH
CVE-2019-10628
all versions
u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' in Snapdra
7.8HIGH
CVE-2019-10615
all versions
u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of
7.8HIGH
CVE-2019-10596
all versions
u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Snapdragon Au
7.8HIGH
CVE-2019-10562
all versions
u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies t
7.8HIGH
CVE-2019-10527
all versions
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address
7.8HIGH
CVE-2020-3701
all versions
Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapd
7.8HIGH
CVE-2020-3700
all versions
Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with n
7.5HIGH
CVE-2020-3699
all versions
Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in
9.8CRITICAL
CVE-2020-3698
all versions
Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Sn
9.8CRITICAL
CVE-2020-3688
all versions
Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto
9.8CRITICAL
CVE-2020-3671
all versions
Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdr
9.8CRITICAL
CVE-2019-14130
all versions
Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in Snapdragon
7.8HIGH
CVE-2019-14124
all versions
Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Compute, Sna
7.8HIGH
CVE-2019-14123
all versions
Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client
7.8HIGH
CVE-2019-14099
all versions
Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdragon Auto,
7.8HIGH
CVE-2019-10580
all versions
When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already fre
7.8HIGH
CVE-2020-3676
all versions
Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto,
7.8HIGH
CVE-2020-3663
all versions
Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto,
9.8CRITICAL
CVE-2020-3662
all versions
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Com
9.8CRITICAL
CVE-2020-3661
all versions
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due to lack o
9.8CRITICAL
CVE-2020-3660
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2020-3658
all versions
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdrago
9.1CRITICAL
CVE-2020-3642
all versions
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL after free/
7.8HIGH
CVE-2020-3635
all versions
Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snapdragon Com
7.8HIGH
CVE-2020-3626
all versions
Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Co
7.8HIGH
CVE-2019-14094
all versions
Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdra
7.8HIGH
CVE-2019-14092
all versions
System Services exports services without permission protect and can lead to information exposure in Snapdragon Industrial IOT, Sna
5.5MEDIUM
CVE-2019-14091
all versions
Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2019-14076
all versions
Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Snapdragon A
7.8HIGH
CVE-2019-10626
all versions
Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snap
5.5MEDIUM
CVE-2019-10597
all versions
kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2020-3645
all versions
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdr
7.5HIGH
CVE-2020-3641
all versions
Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto,
9.8CRITICAL
CVE-2020-3633
all versions
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or n
9.8CRITICAL
CVE-2020-3630
all versions
Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Compute, Snap
7.8HIGH
CVE-2020-3625
all versions
When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snap
7.8HIGH
CVE-2020-3623
all versions
kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130
7.8HIGH
CVE-2020-3618
all versions
NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Snapdragon W
7.8HIGH
CVE-2020-3610
all versions
Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as there is no
7.8HIGH
CVE-2019-14077
all versions
Out of bound memory access while processing ese transmit command due to passing Response buffer received from user in Snapdragon A
7.8HIGH
CVE-2019-14067
all versions
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channe
5.5MEDIUM
CVE-2019-14066
all versions
Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Numbers or check
7.8HIGH
CVE-2019-14054
all versions
Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boo
7.8HIGH
CVE-2019-14053
all versions
When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where the mode
7.1HIGH
CVE-2019-14043
all versions
Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto, Snapdrag
7.1HIGH
CVE-2019-14042
all versions
Out of bound read in fingerprint application due to requested data assigned to a local buffer without length check in Snapdrago
7.1HIGH
CVE-2019-14131
all versions
Out of bound write can occur in radio measurement request if STA receives multiple invalid rrm measurement request from AP in Snap
9.8CRITICAL
CVE-2019-14127
all versions
Possible buffer overflow while playing mkv clip due to lack of validation of atom size buffer in Snapdragon Auto, Snapdragon Compu
9.8CRITICAL
CVE-2019-14122
all versions
Memory failure in SKB if it fails to add the requested padding to the skb in low memory targets or targets with major memory fr
7.8HIGH
CVE-2019-14114
all versions
Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snapdragon Aut
9.8CRITICAL
CVE-2019-14113
all versions
Buffer overflow can occur in WLAN firmware while unwraping data using CCMP cipher suite during parsing of EAPOL handshake frame
9.8CRITICAL
CVE-2019-14112
all versions
Potential buffer overflow while processing CBF frames due to lack of check of buffer length before copy in Snapdragon Auto, Snapdr
9.8CRITICAL
CVE-2019-14111
all versions
Possible buffer overflow while handling NAN reception of NMF in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snap
9.8CRITICAL
CVE-2019-14110
all versions
Buffer overflow can occur in function wlan firmware while copying association frame content if frame length is more than the maxim
9.8CRITICAL
CVE-2019-14075
all versions
Null pointer dereference issue in radio interface layer due to lack of null check in sapmodule destructor in Snapdragon Auto, Snap
5.5MEDIUM
CVE-2019-14070
all versions
Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdra
7.0HIGH
CVE-2019-14009
all versions
Out of bound memory access while processing TZ command handler due to improper input validation on response length received from u
7.8HIGH
CVE-2019-14007
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.5MEDIUM
CVE-2019-10624
all versions
While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type cop
7.8HIGH
CVE-2019-10623
all versions
Possible integer overflow can happen in host driver while processing user controlled string due to improper validation on data rec
7.1HIGH
CVE-2019-10622
all versions
Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace i
9.1CRITICAL
CVE-2019-10621
all versions
Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function in Snapdra
7.8HIGH
CVE-2019-10574
all versions
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute,
7.1HIGH
CVE-2019-10556
all versions
Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer overflow
7.8HIGH
CVE-2019-10547
all versions
When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snapdragon Aut
7.8HIGH
CVE-2019-10523
all versions
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Compute, Snap
5.5MEDIUM
CVE-2019-10483
all versions
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon Auto, Snap
5.5MEDIUM
CVE-2019-14098
all versions
Possible buffer overflow in data offload handler due to lack of check of keydata length when copying data in Snapdragon Auto, Snap
9.8CRITICAL
CVE-2019-14097
all versions
Possible buffer overflow in WLAN Parser due to lack of length check when copying data in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2019-14095
all versions
Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specification in S
9.8CRITICAL
CVE-2019-14083
all versions
While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is
9.8CRITICAL
CVE-2019-14072
all versions
Unhandled paging request is observed due to dereferencing an already freed object because of race condition between sparse free an
7.0HIGH
CVE-2019-14071
all versions
Compromised reset handler may bypass access control due to AC config is being reset if debug path is enabled to collect secure or
7.8HIGH
CVE-2019-14068
all versions
Out of bound access in msm routing due to lack of check of size before accessing in Snapdragon Auto, Snapdragon Compute, Snapdrago
7.8HIGH
CVE-2019-14061
all versions
Null-pointer dereference can occur while accessing the segment element info when it is not allocated and assigned in Snapdragon Au
7.5HIGH
CVE-2019-14032
all versions
Memory use after free issue in audio due to lack of resource control in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer I
7.8HIGH
CVE-2019-14031
all versions
Buffer overflow can occur while parsing RSN IE containing list of PMK ID`s which are more than the buffer size in Snapdragon Auto,
9.8CRITICAL
CVE-2019-14030
all versions
The size of a buffer is determined by addition and multiplications operations that have the potential to overflow due to lack of b
7.8HIGH
CVE-2019-14029
all versions
Use-after-free in graphics module due to destroying already queued syncobj in error case in Snapdragon Auto, Snapdragon Compute, S
7.8HIGH
CVE-2019-14028
all versions
Buffer overwrite during memcpy due to lack of check on SSID length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.8HIGH
CVE-2019-14027
all versions
Buffer overflow due to lack of upper bound check on channel length which is used for a loop. in Snapdragon Compute, Snapdragon Con
7.8HIGH
CVE-2019-14026
all versions
Possible buffer overflow in WLAN WMI handler due to lack of ssid length check when copying data in Snapdragon Auto, Snapdragon Com
7.8HIGH
CVE-2019-14015
all versions
A stack-based buffer overflow exists in the initialization of the identification stage due to lack of check on the number of templ
7.8HIGH
CVE-2019-14000
all versions
Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption
7.8HIGH
CVE-2019-10612
all versions
UTCB object has a function pointer called by the reaper to deallocate its memory resources and this address can potentially be cor
9.8CRITICAL
CVE-2019-10604
all versions
Possibility of heap-buffer-overflow during last iteration of loop while populating image version information in diag command respo
7.8HIGH
CVE-2019-10591
all versions
Null pointer dereference can happen when parsing udta atom which is non-standard and having invalid depth in Snapdragon Auto, Snap
7.5HIGH
CVE-2019-10577
all versions
Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of s
9.1CRITICAL
CVE-2019-10546
all versions
Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2019-14063
all versions
Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Co
9.1CRITICAL
CVE-2019-14060
all versions
Uninitialized stack data gets used If memory is not allocated for blob or if the allocated blob is less than the struct size requi
7.8HIGH
CVE-2019-14057
all versions
Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Aut
9.1CRITICAL
CVE-2019-14055
all versions
Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer acc
7.8HIGH
CVE-2019-14041
all versions
During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating messag
7.8HIGH
CVE-2019-14002
all versions
APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon
7.8HIGH
CVE-2019-10590
all versions
Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, S
9.8CRITICAL
CVE-2019-10567
all versions
There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing command
7.8HIGH
CVE-2019-2267
all versions
Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in Snapdragon
7.8HIGH
CVE-2019-14034
all versions
Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon Auto, Snapd
7.8HIGH
CVE-2019-14024
all versions
Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon M
7.8HIGH
CVE-2019-14023
all versions
String format issue will occur while processing HLOS data as there is no user input validation to ensure inputs are properly NULL
7.8HIGH
CVE-2019-14017
all versions
Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdrag
9.8CRITICAL
CVE-2019-14016
all versions
Integer overflow occurs while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit
9.8CRITICAL
CVE-2019-14014
all versions
Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdrago
9.8CRITICAL
CVE-2019-14013
all versions
While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read in
9.8CRITICAL
CVE-2019-14010
all versions
The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map
7.5HIGH
CVE-2019-14008
all versions
Possible null pointer dereference issue in location assistance data processing due to missing null check on resources before using
7.5HIGH
CVE-2019-14006
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdrago
9.8CRITICAL
CVE-2019-14005
all versions
Buffer overflow occur while playing the clip which is nonstandard due to lack of check of size duration in Snapdragon Auto, Snapdr
9.8CRITICAL
CVE-2019-14004
all versions
Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snap
9.8CRITICAL
CVE-2019-14003
all versions
Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment information in Sna
7.5HIGH
CVE-2019-10611
all versions
Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon
9.8CRITICAL
CVE-2019-10585
all versions
Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use a
7.8HIGH
CVE-2019-10583
all versions
Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Compute, Sna
7.8HIGH
CVE-2019-10582
all versions
Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consum
7.8HIGH
CVE-2019-10581
all versions
NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to use after f
9.8CRITICAL
CVE-2019-10579
all versions
Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon C
9.1CRITICAL
CVE-2019-10578
all versions
Null pointer dereference can occur while parsing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5HIGH
CVE-2019-10558
all versions
While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DS
7.8HIGH
CVE-2019-10532
all versions
Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Sna
9.8CRITICAL
CVE-2019-10614
all versions
Out of boundary access is possible as there is no validation of data accessed against the received size of the packet in case of m
9.8CRITICAL
CVE-2019-10600
all versions
Use of local variable as argument to netlink CB callback goes out of it scope when callback triggered lead to invalid stack memory
7.8HIGH
CVE-2019-10584
all versions
Possibility of out of bound access in debug queue, if packet size field is corrupted in Snapdragon Auto, Snapdragon Compute, Snapd
7.8HIGH
CVE-2019-10564
all versions
Possible OOB issue in EEPROM due to lack of check while accessing memory map array at the time of reading operation in Snapdragon
7.8HIGH
CVE-2019-10544
all versions
Improper length check on source buffer to handle userspace data received can lead to out-of-bound access in diag handlers in Snapd
7.8HIGH
CVE-2019-10537
all versions
Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length c
7.8HIGH
CVE-2019-10536
all versions
Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is not set t
7.8HIGH
CVE-2019-10518
all versions
Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon Compute, Sn
7.8HIGH
CVE-2019-10517
all versions
Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Compute, Snapd
7.8HIGH
CVE-2019-10513
all versions
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snap
5.5MEDIUM
CVE-2019-10482
all versions
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential s
5.9MEDIUM
CVE-2019-2338
all versions
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure
7.1HIGH
CVE-2019-2337
all versions
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause
7.5HIGH
CVE-2019-2321
all versions
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Au
7.8HIGH
CVE-2019-2320
all versions
Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Comp
9.8CRITICAL
CVE-2019-2319
all versions
HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd
7.8HIGH
CVE-2019-10592
all versions
Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check on the ma
7.8HIGH
CVE-2019-10571
all versions
Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Auto, Snapdr
7.8HIGH
CVE-2019-10559
all versions
Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corrup
9.8CRITICAL
CVE-2019-10511
all versions
Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum
9.8CRITICAL
CVE-2019-10493
all versions
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdra
9.8CRITICAL
CVE-2019-10485
all versions
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons
7.5HIGH
CVE-2019-10484
all versions
Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated dur
5.5MEDIUM
CVE-2019-2339
all versions
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdr
7.8HIGH
CVE-2019-2336
all versions
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdr
5.5MEDIUM
CVE-2019-2335
all versions
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdr
7.5HIGH
CVE-2019-2329
all versions
Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application. in Snapdr
7.8HIGH
CVE-2019-2315
all versions
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure enviro
7.8HIGH
CVE-2019-2303
all versions
SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute
9.8CRITICAL
CVE-2019-2289
all versions
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon A
9.8CRITICAL
CVE-2019-2271
all versions
Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdrag
9.8CRITICAL
CVE-2019-2251
all versions
If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially cause stack bu
7.8HIGH
CVE-2019-10566
all versions
Buffer overflow can occur in wlan module if supported rates or extended rates element length is greater than max rate set length i
7.8HIGH
CVE-2019-10490
all versions
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto
5.5MEDIUM
CVE-2018-13916
all versions
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin