Snapdragon 870 5g Mobile Platform Firmware
by Qualcomm
CVEs (100)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33038 | Med | 0.44 | 6.7 | 0.00 | Jan 2, 2024 | Memory corruption while receiving a message in Bus Socket Transport Server. | ||
| CVE-2023-22668 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Audio while invoking IOCTLs calls from the user-space. | ||
| CVE-2023-22383 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in camera while installing a fd for a particular DMA buffer. | ||
| CVE-2023-21634 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM. | ||
| CVE-2023-28570 | Med | 0.44 | 6.7 | 0.00 | Nov 7, 2023 | Memory corruption while processing audio effects. | ||
| CVE-2023-28572 | Med | 0.43 | 6.6 | 0.00 | Nov 7, 2023 | Memory corruption in WLAN HOST while processing the WLAN scan descriptor list. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||
| CVE-2026-24077 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | ||
| CVE-2025-59610 | Med | 0.42 | 6.4 | 0.00 | Jun 1, 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | ||
| CVE-2025-47384 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when MAC configures config id greater than supported maximum value. | ||
| CVE-2025-47371 | Med | 0.42 | 6.5 | 0.00 | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. | ||
| CVE-2024-33037 | Med | 0.40 | 6.1 | 0.00 | Dec 2, 2024 | Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. | ||
| CVE-2024-23357 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | ||
| CVE-2023-33065 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | Information disclosure in Audio while accessing AVCS services from ADSP payload. | ||
| CVE-2023-28554 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | ||
| CVE-2023-28553 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. | ||
| CVE-2023-28586 | Med | 0.39 | 6.0 | 0.00 | Dec 5, 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | ||
| CVE-2023-33076 | Med | 0.38 | 5.9 | 0.00 | Feb 6, 2024 | Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | ||
| CVE-2024-33043 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. |
- risk 0.44cvss 6.7epss 0.00
Memory corruption while receiving a message in Bus Socket Transport Server.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Audio while invoking IOCTLs calls from the user-space.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in camera while installing a fd for a particular DMA buffer.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing audio effects.
- risk 0.43cvss 6.6epss 0.00
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- risk 0.42cvss 6.4epss 0.00
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when MAC configures config id greater than supported maximum value.
- risk 0.42cvss 6.5epss 0.00
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
- risk 0.40cvss 6.1epss 0.00
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
- risk 0.40cvss 6.2epss 0.00
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in Audio while accessing AVCS services from ADSP payload.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in WLAN Host when processing WMI event command.
- risk 0.39cvss 6.0epss 0.00
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
- risk 0.38cvss 5.9epss 0.00
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
Page 5 of 5