Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21438 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while IOCTL call is invoked from user-space to read board data. | ||
| CVE-2025-21437 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing memory map or unmap IOCTL operations simultaneously. | ||
| CVE-2025-21436 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads. | ||
| CVE-2025-21423 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption occurs when handling client calls to EnableTestMode through an Escape call. | ||
| CVE-2025-21421 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing escape code in API. | ||
| CVE-2024-45557 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation. | ||
| CVE-2024-43067 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory. | ||
| CVE-2024-43066 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while handling file descriptor during listener registration/de-registration. | ||
| CVE-2024-43058 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing IOCTL calls. | ||
| CVE-2025-21424 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while calling the NPU driver APIs concurrently. | ||
| CVE-2024-53034 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset. | ||
| CVE-2024-53033 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address. | ||
| CVE-2024-53032 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur in keyboard virtual device due to guest VM interaction. | ||
| CVE-2024-53031 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53030 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing input message passed from FE driver. | ||
| CVE-2024-53029 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53028 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while processing message from frontend during allocation. | ||
| CVE-2024-53024 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption in display driver while detaching a device. | ||
| CVE-2024-53023 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while accessing a variable during extended back to back tests. | ||
| CVE-2024-53022 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during communication between primary and guest VM. | ||
| CVE-2024-53014 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while validating ports and channels in Audio driver. | ||
| CVE-2024-53012 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur due to improper input validation in clock device. | ||
| CVE-2024-53011 | Hig | 0.51 | 7.9 | 0.00 | Mar 3, 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. | ||
| CVE-2024-49836 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during the synchronization of the camera`s frame processing pipeline. | ||
| CVE-2024-45580 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. | ||
| CVE-2024-43062 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization. | ||
| CVE-2024-43061 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive. | ||
| CVE-2024-43060 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. | ||
| CVE-2024-43059 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | ||
| CVE-2024-43057 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing command in Glink linux. | ||
| CVE-2024-43055 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing camera use case IOCTL call. | ||
| CVE-2024-49843 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while processing IOCTL from user space to handle GPU AHB bus error. | ||
| CVE-2024-49840 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. | ||
| CVE-2024-49837 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while reading CPU state data during guest VM suspend. | ||
| CVE-2024-49834 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. | ||
| CVE-2024-49833 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption can occur in the camera when an invalid CID is used. | ||
| CVE-2024-49832 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption in Camera due to unusually high number of nodes passed to AXI port. | ||
| CVE-2024-45584 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace. | ||
| CVE-2024-45582 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while validating number of devices in Camera kernel . | ||
| CVE-2024-45573 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption may occour while generating test pattern due to negative indexing of display ID. | ||
| CVE-2024-45571 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. | ||
| CVE-2024-45561 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while handling IOCTL call from user-space to set latency level. | ||
| CVE-2024-45560 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | ||
| CVE-2024-38418 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while parsing the memory map info in IOCTL calls. | ||
| CVE-2024-45553 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | ||
| CVE-2024-45550 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls. | ||
| CVE-2024-45548 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call. | ||
| CVE-2024-45547 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality. | ||
| CVE-2024-45546 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space. | ||
| CVE-2024-45542 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while IOCTL call is invoked from user-space to read board data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing memory map or unmap IOCTL operations simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape code in API.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling file descriptor during listener registration/de-registration.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while calling the NPU driver APIs concurrently.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing input message passed from FE driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while processing message from frontend during allocation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in display driver while detaching a device.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while accessing a variable during extended back to back tests.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during communication between primary and guest VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while validating ports and channels in Audio driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur due to improper input validation in clock device.
- risk 0.51cvss 7.9epss 0.00
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing command in Glink linux.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing camera use case IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading CPU state data during guest VM suspend.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while power-up or power-down sequence of the camera sensor.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur in the camera when an invalid CID is used.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while validating number of devices in Camera kernel .
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL call from user-space to set latency level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while parsing the memory map info in IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
Page 24 of 61