Snapdragon 480\+ 5g Mobile Platform \(sm4350 Ac\) Firmware
by Qualcomm
CVEs (37)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21479 | Hig | 0.68 | 8.6 | 0.01 | KEV | Jun 3, 2025 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | |
| CVE-2025-27034 | Cri | 0.64 | 9.8 | 0.00 | Sep 24, 2025 | Memory corruption while selecting the PLMN from SOR failed list. | ||
| CVE-2024-33035 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | ||
| CVE-2024-23383 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when kernel driver attempts to trigger hardware fences. | ||
| CVE-2024-23381 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU. | ||
| CVE-2025-21488 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. | ||
| CVE-2025-21487 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | ||
| CVE-2025-21484 | Hig | 0.53 | 8.2 | 0.00 | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | ||
| CVE-2024-53026 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | ||
| CVE-2024-53021 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while processing goodbye RTCP packet from network. | ||
| CVE-2024-53020 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | ||
| CVE-2024-53019 | Hig | 0.53 | 8.2 | 0.00 | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. | ||
| CVE-2025-47348 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing identity credential operations in the trusted application. | ||
| CVE-2025-47382 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while loading an invalid firmware in boot loader. | ||
| CVE-2025-27063 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption during video playback when video session open fails with time out error. | ||
| CVE-2025-27054 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption while processing a malformed license file during reboot. | ||
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2025-21481 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. | ||
| CVE-2025-27062 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | ||
| CVE-2024-43066 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while handling file descriptor during listener registration/de-registration. |
- risk 0.68cvss 8.6epss 0.01
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- risk 0.64cvss 9.8epss 0.00
Memory corruption while selecting the PLMN from SOR failed list.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when kernel driver attempts to trigger hardware fences.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
- risk 0.53cvss 8.2epss 0.00
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while processing goodbye RTCP packet from network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
- risk 0.53cvss 8.2epss 0.00
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing identity credential operations in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while loading an invalid firmware in boot loader.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during video playback when video session open fails with time out error.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a malformed license file during reboot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while performing private key encryption in trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling client exceptions, allowing unauthorized channel access.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling file descriptor during listener registration/de-registration.
Page 1 of 2