Snapdragon 888\+ 5g Mobile Platform \(sm8350 Ac\) Firmware
by Qualcomm
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43065 | Hig | 0.46 | 7.1 | 0.00 | Apr 7, 2025 | Cryptographic issues while generating an asymmetric key pair for RKP use cases. | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. | ||
| CVE-2024-53015 | Med | 0.43 | 6.6 | 0.00 | Jun 3, 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. | ||
| CVE-2024-45540 | Med | 0.43 | 6.6 | 0.00 | Apr 7, 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. | ||
| CVE-2025-21465 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while processing the hash segment in an MBN file. | ||
| CVE-2025-21464 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | Information disclosure while reading data from an image using specified offset and size parameters. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2025-27041 | Med | 0.36 | 5.5 | 0.00 | Oct 9, 2025 | Transient DOS while processing video packets received from video firmware. | ||
| CVE-2024-43046 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
- risk 0.46cvss 7.1epss 0.00
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while processing IOCTL command to handle buffers associated with a session.
- risk 0.43cvss 6.6epss 0.00
Memory corruption while invoking IOCTL map buffer request from userspace.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing the hash segment in an MBN file.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while reading data from an image using specified offset and size parameters.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing video packets received from video firmware.
- risk 0.36cvss 5.5epss 0.00
There may be information disclosure during memory re-allocation in TZ Secure OS.
Page 2 of 2