Sd460 Firmware
by Qualcomm
CVEs (396)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2021-35080 | Med | 0.42 | 6.5 | 0.00 | Jun 14, 2022 | Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-30346 | Med | 0.42 | 6.5 | 0.00 | Jun 14, 2022 | RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-30345 | Med | 0.42 | 6.5 | 0.00 | Jun 14, 2022 | RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-30348 | Med | 0.42 | 6.5 | 0.00 | Jan 3, 2022 | Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2021-1960 | Med | 0.42 | 6.5 | 0.00 | Sep 9, 2021 | Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… | ||
| CVE-2020-11220 | Med | 0.42 | 6.4 | 0.00 | Mar 17, 2021 | While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT,… | ||
| CVE-2023-28569 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28568 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL when reception status handler is called. | ||
| CVE-2023-28566 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling the WMI state info command. | ||
| CVE-2023-28563 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. | ||
| CVE-2022-40533 | Med | 0.40 | 6.2 | 0.00 | Jun 6, 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | ||
| CVE-2022-22075 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2023 | Information Disclosure in Graphics during GPU context switch. | ||
| CVE-2022-25679 | Med | 0.40 | 6.2 | 0.00 | Nov 15, 2022 | Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-35135 | Med | 0.40 | 6.2 | 0.00 | Sep 2, 2022 | A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-35079 | Med | 0.40 | 6.2 | 0.00 | Jun 14, 2022 | Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-30314 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2022 | Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1929 | Med | 0.40 | 6.2 | 0.00 | Sep 8, 2021 | Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-1904 | Med | 0.40 | 6.2 | 0.01 | Sep 8, 2021 | Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &… |
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.42cvss 6.5epss 0.00
Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.42cvss 6.5epss 0.00
RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- risk 0.42cvss 6.5epss 0.00
RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- risk 0.42cvss 6.5epss 0.00
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…
- risk 0.42cvss 6.5epss 0.00
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
- risk 0.42cvss 6.4epss 0.00
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT,…
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling command through WMI interfaces.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL when reception status handler is called.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling the WMI state info command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in IOE Firmware while handling WMI command.
- risk 0.40cvss 6.2epss 0.00
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
- risk 0.40cvss 6.2epss 0.00
Information Disclosure in Graphics during GPU context switch.
- risk 0.40cvss 6.2epss 0.00
Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.40cvss 6.2epss 0.00
Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.00
Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.40cvss 6.2epss 0.01
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…
Page 19 of 20