Snapdragon 460 Mobile Platform Firmware
by Qualcomm
CVEs (204)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21378 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | ||
| CVE-2026-21376 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | ||
| CVE-2026-21375 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | ||
| CVE-2026-21374 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | ||
| CVE-2026-21373 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | ||
| CVE-2026-21372 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. | ||
| CVE-2026-21371 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. | ||
| CVE-2025-47389 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | ||
| CVE-2025-59600 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | ||
| CVE-2025-47386 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | ||
| CVE-2025-47379 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | ||
| CVE-2025-47377 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | ||
| CVE-2025-47376 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | ||
| CVE-2025-47375 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | ||
| CVE-2025-47373 | Hig | 0.51 | 7.8 | 0.00 | Mar 2, 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | ||
| CVE-2025-47398 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | ||
| CVE-2025-47397 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | ||
| CVE-2025-47348 | Hig | 0.51 | 7.8 | 0.00 | Jan 7, 2026 | Memory corruption while processing identity credential operations in the trusted application. | ||
| CVE-2025-47323 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while routing GPR packets between user and root when handling large data packet. | ||
| CVE-2025-47322 | Hig | 0.51 | 7.8 | 0.00 | Dec 18, 2025 | Memory corruption while handling IOCTL calls to set mode. |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when retrieving output buffer with insufficient size validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when adding user-supplied data without checking available buffer space.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when accessing buffers with invalid length during TA invocation.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing identity credential operations in the trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while routing GPR packets between user and root when handling large data packet.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL calls to set mode.
Page 4 of 11