Snapdragon 4 Gen 2 Mobile Firmware
by Qualcomm
CVEs (200)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27053 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. | ||
| CVE-2025-27061 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2024-53010 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-45557 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation. | ||
| CVE-2024-49834 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. | ||
| CVE-2024-49833 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption can occur in the camera when an invalid CID is used. | ||
| CVE-2024-45553 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | ||
| CVE-2024-38424 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption during GNSS HAL process initialization. | ||
| CVE-2024-38415 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while handling session errors from firmware. | ||
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2024-23356 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption during session sign renewal request calls in HLOS. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption during PlayReady APP usecase while processing TA commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while power-up or power-down sequence of the camera sensor.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur in the camera when an invalid CID is used.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during GNSS HAL process initialization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling session errors from firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during session sign renewal request calls in HLOS.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Page 5 of 10