Snapdragon 429 Mobile Firmware
by Qualcomm
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45554 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent SSR execution due to race condition on the global maps list. | ||
| CVE-2024-53023 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while accessing a variable during extended back to back tests. | ||
| CVE-2024-49834 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. | ||
| CVE-2024-49832 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption in Camera due to unusually high number of nodes passed to AXI port. | ||
| CVE-2024-45573 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption may occour while generating test pattern due to negative indexing of display ID. | ||
| CVE-2024-45561 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while handling IOCTL call from user-space to set latency level. | ||
| CVE-2024-45560 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | ||
| CVE-2024-38418 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while parsing the memory map info in IOCTL calls. | ||
| CVE-2024-33054 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2024-49847 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE. | ||
| CVE-2024-38404 | Hig | 0.49 | 7.5 | 0.00 | Feb 3, 2025 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. | ||
| CVE-2024-43064 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | ||
| CVE-2024-33048 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | ||
| CVE-2024-49829 | Med | 0.44 | 6.7 | 0.00 | May 6, 2025 | Memory corruption can occur during context user dumps due to inadequate checks on buffer length. | ||
| CVE-2024-45568 | Med | 0.44 | 6.7 | 0.00 | May 6, 2025 | Memory corruption due to improper bounds check while command handling in camera-kernel driver. | ||
| CVE-2023-43527 | Med | 0.44 | 6.8 | 0.00 | May 6, 2024 | Information disclosure while parsing dts header atom in Video. | ||
| CVE-2024-49830 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while processing an IOCTL call to set mixer controls. | ||
| CVE-2024-45581 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption while sound model registration for voice activation with audio kernel driver. | ||
| CVE-2024-45570 | Med | 0.43 | 6.6 | 0.00 | May 6, 2025 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while accessing a variable during extended back to back tests.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while power-up or power-down sequence of the camera sensor.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL call from user-space to set latency level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while parsing the memory map info in IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
- risk 0.49cvss 7.5epss 0.00
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
- risk 0.44cvss 6.7epss 0.00
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
- risk 0.44cvss 6.8epss 0.00
Information disclosure while parsing dts header atom in Video.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing an IOCTL call to set mixer controls.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while sound model registration for voice activation with audio kernel driver.
- risk 0.43cvss 6.6epss 0.00
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
Page 2 of 3