Snapdragon 429 Mobile Platform Firmware
by Qualcomm
CVEs (87)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45552 | Hig | 0.53 | 8.2 | 0.00 | Apr 7, 2025 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | ||
| CVE-2024-23359 | Hig | 0.53 | 8.2 | 0.00 | Sep 2, 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | ||
| CVE-2023-24849 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | ||
| CVE-2023-24848 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | ||
| CVE-2023-22385 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | ||
| CVE-2025-47320 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while processing MFC channel configuration during music playback. | ||
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2024-43067 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory. | ||
| CVE-2024-43066 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while handling file descriptor during listener registration/de-registration. | ||
| CVE-2024-43053 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information. | ||
| CVE-2024-43052 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while processing API calls to NPU with invalid input. | ||
| CVE-2024-43050 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | ||
| CVE-2024-43049 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. | ||
| CVE-2024-43048 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. | ||
| CVE-2024-38424 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption during GNSS HAL process initialization. | ||
| CVE-2024-38423 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU page table switch. | ||
| CVE-2024-38422 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | ||
| CVE-2024-38410 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice. | ||
| CVE-2024-38409 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while station LL statistic handling. | ||
| CVE-2024-38407 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver. |
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- risk 0.53cvss 8.2epss 0.00
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing MFC channel configuration during music playback.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling file descriptor during listener registration/de-registration.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing API calls to NPU with invalid input.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during GNSS HAL process initialization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU page table switch.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while station LL statistic handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Page 2 of 5