Sm8550p Firmware
by Qualcomm
CVEs (342)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43538 | Cri | 0.60 | 9.3 | 0.00 | Jun 3, 2024 | Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. | ||
| CVE-2023-28578 | Cri | 0.60 | 9.3 | 0.00 | Mar 4, 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. | ||
| CVE-2023-33072 | Cri | 0.60 | 9.3 | 0.00 | Feb 6, 2024 | Memory corruption in Core while processing control functions. | ||
| CVE-2023-43551 | Cri | 0.59 | 9.1 | 0.00 | Jun 3, 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | ||
| CVE-2023-33054 | Cri | 0.59 | 9.1 | 0.00 | Dec 5, 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. | ||
| CVE-2023-28574 | Cri | 0.59 | 9.0 | 0.00 | Nov 7, 2023 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | ||
| CVE-2023-28540 | Cri | 0.59 | 9.1 | 0.00 | Oct 3, 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | ||
| CVE-2020-11222 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile | ||
| CVE-2020-11190 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11189 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11188 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11171 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-11166 | Cri | 0.59 | 9.1 | 0.01 | Mar 17, 2021 | Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2026-25277 | Hig | 0.57 | 8.8 | 0.00 | Jun 1, 2026 | Memory corruption while using Strongbox due to buffer overflow. | ||
| CVE-2026-25276 | Hig | 0.57 | 8.8 | 0.00 | Jun 1, 2026 | Memory corruption while using Strongbox due to missing bounds check. | ||
| CVE-2025-47392 | Hig | 0.57 | 8.8 | 0.00 | Apr 6, 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | ||
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2023-43534 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. | ||
| CVE-2023-43520 | Hig | 0.56 | 8.6 | 0.00 | Feb 6, 2024 | Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
- risk 0.60cvss 9.3epss 0.00
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core Services while executing the command for removing a single event listener.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core while processing control functions.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
- risk 0.59cvss 9.0epss 0.00
Memory corruption in core services when Diag handler receives a command to configure event listeners.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- risk 0.59cvss 9.1epss 0.01
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.59cvss 9.1epss 0.01
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.57cvss 8.8epss 0.00
Memory corruption while using Strongbox due to buffer overflow.
- risk 0.57cvss 8.8epss 0.00
Memory corruption while using Strongbox due to missing bounds check.
- risk 0.57cvss 8.8epss 0.00
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.56cvss 8.6epss 0.00
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
- risk 0.56cvss 8.6epss 0.00
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Page 2 of 18