Snapdragon 888\+ 5g Mobile Firmware
by Qualcomm
CVEs (60)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2025-21467 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-49835 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading secure file. | ||
| CVE-2024-45564 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to incorrect reference count update. | ||
| CVE-2024-45554 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent SSR execution due to race condition on the global maps list. | ||
| CVE-2024-49834 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. | ||
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21476 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the channel ID passed by user is not validated and further used. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2023-43550 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2024 | Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading the FW response from the shared queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading secure file.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent access to server info object due to incorrect reference count update.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while power-up or power-down sequence of the camera sensor.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the channel ID passed by user is not validated and further used.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
Page 2 of 3