VYPR

Vendor CVEs

Qualcomm

All CVEs

3,002 total · sorted by risk
  • CVE-2014-9973CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missing in a PlayReady DRM routine.

  • CVE-2014-9972CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.

  • CVE-2014-9971CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.

  • CVE-2014-9969CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.00

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm.

  • CVE-2014-9968CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.

  • CVE-2014-9411CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.

  • CVE-2016-6727CriApr 17, 2017
    risk 0.64cvss 9.8epss 0.03

    The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.

  • CVE-2016-8418CriFeb 8, 2017
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product:…

  • CVE-2016-6725CriNov 25, 2016
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the…

  • CVE-2016-6696CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm internal bug CR 1041130.

  • CVE-2016-6695CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted visualizer data length, aka Qualcomm internal bug CR 1033540.

  • CVE-2016-6694CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via crafted parameter data, aka Qualcomm internal bug CR 1033525.

  • CVE-2016-6693CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via an invalid data length, aka Qualcomm internal bug CR 1027585.

  • CVE-2016-6692CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm MDSS driver in Android before 2016-10-05 allows attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via unknown vectors, aka Qualcomm internal bug CR 1004933.

  • CVE-2016-6691CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with…

  • CVE-2016-5343CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.03

    drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (memory corruption) or possibly…

  • CVE-2016-3929CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823675.

  • CVE-2016-3927CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823244.

  • CVE-2016-3926CriOct 10, 2016
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5, 5X, 6, and 6P devices has unknown impact and attack vectors, aka internal bug 28823953.

  • CVE-2016-5344CriAug 30, 2016
    risk 0.64cvss 9.8epss 0.02

    Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impact via a large size…

  • CVE-2015-0573CriAug 7, 2016
    risk 0.64cvss 9.8epss 0.02

    drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (invalid pointer dereference) or possibly…

  • CVE-2014-9410CriAug 7, 2016
    risk 0.64cvss 9.8epss 0.01

    The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate a certain id value, which allows…

  • CVE-2014-9902CriAug 5, 2016
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android…

  • CVE-2006-6024CriNov 21, 2006
    risk 0.64cvss 9.8epss 0.01

    Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack. NOTE: Some of these…

  • CVE-2026-21385HigKEVMar 2, 2026
    risk 0.63cvss 7.8epss 0.01

    Memory corruption while using alignments for memory allocation.

  • CVE-2024-43047HigKEVOct 7, 2024
    risk 0.63cvss 7.8epss 0.01

    Memory corruption while maintaining memory maps of HLOS memory.

  • CVE-2023-33063HigKEVDec 5, 2023
    risk 0.63cvss 7.8epss 0.01

    Memory corruption in DSP Services during a remote call from HLOS to DSP.

  • CVE-2020-11261HigKEVJun 9, 2021
    risk 0.63cvss 7.8epss 0.02

    Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2026-25289CriAug 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

  • CVE-2026-25293CriMay 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Buffer overflow due to incorrect authorization in PLC FW

  • CVE-2025-27038HigKEVJun 3, 2025
    risk 0.61cvss 7.5epss 0.01

    Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

  • CVE-2022-22105CriSep 16, 2022
    risk 0.61cvss 9.4epss 0.00

    Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2023-43556CriJun 3, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Hypervisor when platform information mentioned is not aligned.

  • CVE-2023-43538CriJun 3, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

  • CVE-2023-28578CriMar 4, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core Services while executing the command for removing a single event listener.

  • CVE-2023-33072CriFeb 6, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core while processing control functions.

  • CVE-2023-33032CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-21671CriNov 7, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory Corruption in Core during syscall for Sectools Fuse comparison feature.

  • CVE-2023-21651CriAug 8, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.

  • CVE-2022-33288CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.

  • CVE-2022-33269CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.

  • CVE-2022-33231CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to double free in core while initializing the encryption key.

  • CVE-2022-33257CriMar 10, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.

  • CVE-2022-33232CriFeb 12, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.

  • CVE-2022-33219CriJan 9, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.

  • CVE-2021-35122CriSep 2, 2022
    risk 0.60cvss 9.3epss 0.00

    Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35090CriJun 14, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1942CriApr 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…

Page 12 of 61