VYPR

Vendor CVEs

Qualcomm

All CVEs

3,001 total · sorted by risk
  • CVE-2019-10553CriMar 5, 2020
    risk 0.59cvss 9.1epss 0.01

    Multiple Read overflows due to improper length checks while decoding authentication in Cs domain/RAU Reject and TC cmd in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2019-10552CriMar 5, 2020
    risk 0.59cvss 9.1epss 0.01

    Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cmd in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2019-10550CriMar 5, 2020
    risk 0.59cvss 9.1epss 0.01

    Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650,…

  • CVE-2019-14063CriFeb 7, 2020
    risk 0.59cvss 9.1epss 0.01

    Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2019-14057CriFeb 7, 2020
    risk 0.59cvss 9.1epss 0.01

    Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-10579CriJan 21, 2020
    risk 0.59cvss 9.1epss 0.01

    Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in…

  • CVE-2018-13906CriJun 14, 2019
    risk 0.59cvss 9.1epss 0.01

    The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forged application message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…

  • CVE-2018-11932CriFeb 25, 2019
    risk 0.59cvss 9.1epss 0.01

    Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9650,…

  • CVE-2016-10492CriApr 18, 2018
    risk 0.59cvss 9.1epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD…

  • CVE-2015-9124CriApr 18, 2018
    risk 0.59cvss 9.1epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, and SD 810, the device may crash while accessing an invalid pointer or…

  • CVE-2026-25277HigJun 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while using Strongbox due to buffer overflow.

  • CVE-2026-25276HigJun 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while using Strongbox due to missing bounds check.

  • CVE-2025-47392HigApr 6, 2026
    risk 0.57cvss 8.8epss 0.00

    Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

  • CVE-2025-27074HigNov 4, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while processing a GP command response.

  • CVE-2025-27060HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while performing SCM call with malformed inputs.

  • CVE-2025-27059HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while performing SCM call.

  • CVE-2024-38420HigFeb 3, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while configuring a Hypervisor based input virtual device.

  • CVE-2023-21673HigOct 3, 2023
    risk 0.57cvss 8.7epss 0.00

    Improper Access to the VM resource manager can lead to Memory Corruption.

  • CVE-2022-31883HigJun 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.

  • CVE-2021-35123HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.00

    Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT

  • CVE-2020-11259HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11258HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11257HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Memory corruption due to lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11256HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11269HigFeb 22, 2021
    risk 0.57cvss 8.8epss 0.00

    Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-11177HigFeb 22, 2021
    risk 0.57cvss 8.8epss 0.00

    User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2020-11155HigNov 2, 2020
    risk 0.57cvss 8.8epss 0.01

    u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2020-11154HigNov 2, 2020
    risk 0.57cvss 8.8epss 0.01

    u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2020-11114HigNov 2, 2020
    risk 0.57cvss 8.8epss 0.00

    u'Bluetooth devices does not properly restrict the L2CAP payload length allowing users in radio range to cause a buffer overflow via a crafted Link Layer packet(Equivalent to CVE-2019-17060,CVE-2019-17061 and CVE-2019-17517 in Sweyntooth paper)' in Snapdragon Compute, Snapdragon…

  • CVE-2019-2316HigJul 25, 2019
    risk 0.57cvss 8.8epss 0.00

    When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9640, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD…

  • CVE-2018-5881HigJan 18, 2019
    risk 0.57cvss 8.8epss 0.00

    Improper validation of buffer length checks in the lwm2m device management protocol can leads to a buffer overflow in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660,…

  • CVE-2018-5879HigJan 18, 2019
    risk 0.57cvss 8.8epss 0.00

    Improper length check while processing an MQTT message can lead to heap overflow in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660, SDM630, SDM660

  • CVE-2018-11993HigJan 18, 2019
    risk 0.57cvss 8.8epss 0.00

    Improper check while accessing the local memory stack on MQTT connection request can lead to buffer overflow in snapdragon wear in versions MDM9206, MDM9607

  • CVE-2018-11279HigJan 18, 2019
    risk 0.57cvss 8.8epss 0.01

    Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD…

  • CVE-2017-18171HigOct 23, 2018
    risk 0.57cvss 8.8epss 0.01

    Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52,…

  • CVE-2017-18170HigOct 23, 2018
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD…

  • CVE-2018-11982HigSep 20, 2018
    risk 0.57cvss 8.8epss 0.00

    In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 835,…

  • CVE-2018-5876HigJul 6, 2018
    risk 0.57cvss 8.8epss 0.01

    While parsing an mp4 file, a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear.

  • CVE-2018-5875HigJul 6, 2018
    risk 0.57cvss 8.8epss 0.01

    While parsing an mp4 file, an integer overflow leading to a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear.

  • CVE-2018-5874HigJul 6, 2018
    risk 0.57cvss 8.8epss 0.01

    While parsing an mp4 file, a stack-based buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear.

  • CVE-2017-15822HigApr 3, 2018
    risk 0.57cvss 8.8epss 0.00

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing a 802.11 management frame, a buffer overflow may potentially occur.

  • CVE-2016-5861HigAug 16, 2017
    risk 0.57cvss 8.8epss 0.00

    In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.

  • CVE-2023-43534HigFeb 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

  • CVE-2023-43520HigFeb 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.

  • CVE-2020-11303HigOct 20, 2021
    risk 0.56cvss 8.6epss 0.01

    Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2019-10529HigNov 6, 2019
    risk 0.56cvss 8.1epss 0.02

    Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2025-47345HigJan 7, 2026
    risk 0.55cvss 8.4epss 0.00

    Cryptographic issue may occur while encrypting license data.

  • CVE-2024-45555HigJan 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.

  • CVE-2024-21464HigJan 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while processing IPA statistics, when there are no active clients registered.

  • CVE-2024-33056HigDec 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

Page 14 of 61