Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45541 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to read board data. | ||
| CVE-2024-43053 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information. | ||
| CVE-2024-43052 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while processing API calls to NPU with invalid input. | ||
| CVE-2024-43050 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | ||
| CVE-2024-43049 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. | ||
| CVE-2024-43048 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption when invalid input is passed to invoke GPU Headroom API call. | ||
| CVE-2018-11816 | Hig | 0.51 | 7.8 | 0.00 | Nov 26, 2024 | Crafted Binder Request Causes Heap UAF in MediaServer | ||
| CVE-2024-38424 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption during GNSS HAL process initialization. | ||
| CVE-2024-38423 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU page table switch. | ||
| CVE-2024-38422 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | ||
| CVE-2024-38421 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing GPU commands. | ||
| CVE-2024-38419 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | ||
| CVE-2024-38415 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while handling session errors from firmware. | ||
| CVE-2024-38410 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice. | ||
| CVE-2024-38409 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while station LL statistic handling. | ||
| CVE-2024-38407 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver. | ||
| CVE-2024-38406 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2024 | Memory corruption while handling IOCTL calls in JPEG Encoder driver. | ||
| CVE-2024-23369 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. | ||
| CVE-2024-21455 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver. | ||
| CVE-2024-38402 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. | ||
| CVE-2024-38401 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while processing concurrent IOCTL calls. | ||
| CVE-2024-33054 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. | ||
| CVE-2024-33052 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. | ||
| CVE-2024-33042 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. | ||
| CVE-2024-33038 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | ||
| CVE-2024-23356 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption during session sign renewal request calls in HLOS. | ||
| CVE-2024-23355 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2024 | Memory corruption when keymaster operation imports a shared key. | ||
| CVE-2024-23368 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2023-43542 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | ||
| CVE-2024-21476 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the channel ID passed by user is not validated and further used. | ||
| CVE-2024-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2024-26002 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. | ||
| CVE-2023-43550 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2024 | Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. | ||
| CVE-2023-43516 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption when malformed message payload is received from firmware. | ||
| CVE-2023-43513 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | ||
| CVE-2023-33046 | Hig | 0.51 | 7.8 | 0.00 | Feb 6, 2024 | Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. | ||
| CVE-2023-33120 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. | ||
| CVE-2023-33118 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. | ||
| CVE-2023-33117 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. | ||
| CVE-2023-33110 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | ||
| CVE-2023-33085 | Hig | 0.51 | 7.8 | 0.00 | Jan 2, 2024 | Memory corruption in wearables while processing data from AON. | ||
| CVE-2023-33087 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Core while processing RX intent request. | ||
| CVE-2023-33079 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Audio while running invalid audio recording from ADSP. | ||
| CVE-2023-33018 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. | ||
| CVE-2023-33017 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | ||
| CVE-2023-28587 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. | ||
| CVE-2023-28551 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | ||
| CVE-2023-28550 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to read board data.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing API calls to NPU with invalid input.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
- risk 0.51cvss 7.8epss 0.00
Crafted Binder Request Causes Heap UAF in MediaServer
- risk 0.51cvss 7.8epss 0.00
Memory corruption during GNSS HAL process initialization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU page table switch.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing GPU commands.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling session errors from firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while station LL statistic handling.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call for getting group info.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing concurrent IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when user provides data for FM HCI command control operations.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when Alternative Frequency offset value is set to 255.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during session sign renewal request calls in HLOS.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when keymaster operation imports a shared key.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the channel ID passed by user is not validated and further used.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the payload received from firmware is not as per the expected protocol size.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.51cvss 7.8epss 0.00
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when malformed message payload is received from firmware.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.
- risk 0.51cvss 7.8epss 0.00
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in wearables while processing data from AON.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Core while processing RX intent request.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio while running invalid audio recording from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while using the UIM diag command to get the operators name.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Page 25 of 61