Snapdragon Auto
by Qualcomm
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-3657 | Cri | 0.66 | 9.8 | 0.28 | Nov 2, 2020 | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2020-11225 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2021 | Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2020-3692 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2020 | u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in… | ||
| CVE-2019-14111 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2020 | Possible buffer overflow while handling NAN reception of NMF in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018,… | ||
| CVE-2019-14045 | Cri | 0.64 | 9.8 | 0.01 | Mar 5, 2020 | Possible buffer overflow while processing clientlog and serverlog due to lack of validation of data received in logs in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in APQ8096AU, QCS605, SDM439, SM8150, SXR1130 | ||
| CVE-2019-10542 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2019-10531 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439 | ||
| CVE-2019-10538 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2019 | Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice… | ||
| CVE-2019-2276 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2019 | Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music… | ||
| CVE-2018-13911 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2019 | Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150,… | ||
| CVE-2018-13904 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2019 | Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206,… | ||
| CVE-2022-33210 | Hig | 0.55 | 8.4 | 0.00 | Oct 19, 2022 | Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto | ||
| CVE-2022-25680 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto | ||
| CVE-2022-22106 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto | ||
| CVE-2022-22104 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto | ||
| CVE-2022-22102 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto | ||
| CVE-2022-22100 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto | ||
| CVE-2022-22099 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto | ||
| CVE-2022-22098 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2022 | Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon Auto | ||
| CVE-2021-35114 | Hig | 0.55 | 8.4 | 0.00 | Jun 14, 2022 | Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto |
- risk 0.66cvss 9.8epss 0.28
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.64cvss 9.8epss 0.01
Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- risk 0.64cvss 9.8epss 0.01
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in…
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow while handling NAN reception of NMF in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018,…
- risk 0.64cvss 9.8epss 0.01
Possible buffer overflow while processing clientlog and serverlog due to lack of validation of data received in logs in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in APQ8096AU, QCS605, SDM439, SM8150, SXR1130
- risk 0.64cvss 9.8epss 0.01
Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.64cvss 9.8epss 0.01
Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439
- risk 0.64cvss 9.8epss 0.01
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…
- risk 0.64cvss 9.8epss 0.01
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music…
- risk 0.64cvss 9.8epss 0.01
Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150,…
- risk 0.64cvss 9.8epss 0.01
Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206,…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon Auto
- risk 0.55cvss 8.4epss 0.00
Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto
Page 1 of 4