Snapdragon 750g 5g Mobile Platform Firmware
by Qualcomm
CVEs (87)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-53020 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | ||
| CVE-2024-38408 | Hig | 0.53 | 8.2 | 0.00 | Nov 4, 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. | ||
| CVE-2024-23359 | Hig | 0.53 | 8.2 | 0.00 | Sep 2, 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. | ||
| CVE-2023-28585 | Hig | 0.53 | 8.2 | 0.00 | Dec 5, 2023 | Memory corruption while loading an ELF segment in TEE Kernel. | ||
| CVE-2023-28545 | Hig | 0.53 | 8.2 | 0.00 | Nov 7, 2023 | Memory corruption in TZ Secure OS while loading an app ELF. | ||
| CVE-2023-24849 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | ||
| CVE-2023-24848 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | ||
| CVE-2023-22385 | Hig | 0.53 | 8.2 | 0.00 | Oct 3, 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | ||
| CVE-2025-27054 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing a malformed license file during reboot. | ||
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2025-21481 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. | ||
| CVE-2024-38423 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU page table switch. | ||
| CVE-2024-38422 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | ||
| CVE-2024-38415 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while handling session errors from firmware. | ||
| CVE-2024-23356 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption during session sign renewal request calls in HLOS. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2023-43513 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | ||
| CVE-2023-33120 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. | ||
| CVE-2023-33118 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
- risk 0.53cvss 8.2epss 0.00
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
- risk 0.53cvss 8.2epss 0.00
Memory corruption while loading an ELF segment in TEE Kernel.
- risk 0.53cvss 8.2epss 0.00
Memory corruption in TZ Secure OS while loading an app ELF.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- risk 0.53cvss 8.2epss 0.00
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- risk 0.53cvss 8.2epss 0.00
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a malformed license file during reboot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while performing private key encryption in trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU page table switch.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling session errors from firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during session sign renewal request calls in HLOS.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.
Page 2 of 5