Snapdragon 855\+ Mobile Firmware
by Qualcomm
CVEs (28)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43538 | Cri | 0.60 | 9.3 | 0.00 | Jun 3, 2024 | Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. | ||
| CVE-2023-28578 | Cri | 0.60 | 9.3 | 0.00 | Mar 4, 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. | ||
| CVE-2024-21468 | Hig | 0.55 | 8.4 | 0.00 | Apr 1, 2024 | Memory corruption when there is failed unmap operation in GPU. | ||
| CVE-2023-33066 | Hig | 0.55 | 8.4 | 0.00 | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. | ||
| CVE-2025-21427 | Hig | 0.53 | 8.2 | 0.00 | Jul 8, 2025 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2024-21477 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | ||
| CVE-2023-43529 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | ||
| CVE-2023-33101 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | Transient DOS while processing DL NAS TRANSPORT message with payload length 0. | ||
| CVE-2023-33099 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. | ||
| CVE-2023-33104 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing PDU Release command with a parameter PDU ID out of range. |
- risk 0.60cvss 9.3epss 0.00
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core Services while executing the command for removing a single event listener.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when there is failed unmap operation in GPU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Audio while processing RT proxy port register driver.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
Page 1 of 2