Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27058 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing packet data with exceedingly large packet. | ||
| CVE-2025-27056 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during sub-system restart while processing clean-up to free up resources. | ||
| CVE-2025-27055 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during the image encoding process. | ||
| CVE-2025-27052 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing data packets in diag received from Unix clients. | ||
| CVE-2025-27051 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing command message in WLAN Host. | ||
| CVE-2025-27050 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing event close when client process terminates abruptly. | ||
| CVE-2025-27047 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing the TESTPATTERNCONFIG escape path. | ||
| CVE-2025-27046 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing multiple simultaneous escape calls. | ||
| CVE-2025-27044 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while executing timestamp video decode command with large input values. | ||
| CVE-2025-27043 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing manipulated payload in video firmware. | ||
| CVE-2025-27042 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. | ||
| CVE-2025-21466 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while processing a private escape command in an event trigger. | ||
| CVE-2025-21445 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host. | ||
| CVE-2025-21444 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while copying the result to the transmission queue in EMAC. | ||
| CVE-2025-21432 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. | ||
| CVE-2025-27031 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed. | ||
| CVE-2025-21486 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. | ||
| CVE-2025-21485 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC. | ||
| CVE-2024-53010 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. | ||
| CVE-2025-37901 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs On Qualcomm chipsets not all GPIOs are wakeup capable. Those GPIOs do not have a corresponding MPM pin and should not be handled inside the… | ||
| CVE-2025-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing escape code, when DisplayId is passed with large unsigned value. | ||
| CVE-2025-21470 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. | ||
| CVE-2025-21469 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. | ||
| CVE-2025-21468 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. | ||
| CVE-2025-21467 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. | ||
| CVE-2025-21462 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit. | ||
| CVE-2025-21460 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously. | ||
| CVE-2025-21453 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-49842 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. | ||
| CVE-2024-49841 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling. | ||
| CVE-2024-49835 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while reading secure file. | ||
| CVE-2024-45579 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check. | ||
| CVE-2024-45578 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while acquire and update IOCTLs during IFE output resource ID validation. | ||
| CVE-2024-45577 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. | ||
| CVE-2024-45576 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while prociesing command buffer buffer in OPE module. | ||
| CVE-2024-45575 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption Camera kernel when large number of devices are attached through userspace. | ||
| CVE-2024-45574 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during array access in Camera kernel due to invalid index from invalid command data. | ||
| CVE-2024-45567 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while encoding JPEG format. | ||
| CVE-2024-45566 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent buffer access due to modification of the reference count. | ||
| CVE-2024-45565 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption when blob structure is modified by user-space after kernel verification. | ||
| CVE-2024-45564 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent access to server info object due to incorrect reference count update. | ||
| CVE-2024-45554 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during concurrent SSR execution due to race condition on the global maps list. | ||
| CVE-2025-21447 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption may occur while processing device IO control call for session control. | ||
| CVE-2025-21443 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing message content in eAVB. | ||
| CVE-2025-21442 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while transmitting packet mapping information with invalid header payload size. | ||
| CVE-2025-21441 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | ||
| CVE-2025-21440 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | ||
| CVE-2025-21439 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing packet data with exceedingly large packet.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during sub-system restart while processing clean-up to free up resources.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the image encoding process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing data packets in diag received from Unix clients.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing command message in WLAN Host.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing event close when client process terminates abruptly.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the TESTPATTERNCONFIG escape path.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing multiple simultaneous escape calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while executing timestamp video decode command with large input values.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing manipulated payload in video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing video packets received from video firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a private escape command in an event trigger.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying the result to the transmission queue in EMAC.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while retrieving the CBOR data from TA.
- risk 0.51cvss 7.8epss 0.00
memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: irqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs On Qualcomm chipsets not all GPIOs are wakeup capable. Those GPIOs do not have a corresponding MPM pin and should not be handled inside the…
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading the FW response from the shared queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading secure file.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while prociesing command buffer buffer in OPE module.
- risk 0.51cvss 7.8epss 0.00
Memory corruption Camera kernel when large number of devices are attached through userspace.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during array access in Camera kernel due to invalid index from invalid command data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while encoding JPEG format.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent buffer access due to modification of the reference count.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when blob structure is modified by user-space after kernel verification.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent access to server info object due to incorrect reference count update.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while processing device IO control call for session control.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing message content in eAVB.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while transmitting packet mapping information with invalid header payload size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.
Page 23 of 61