Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28546 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. | ||
| CVE-2023-33059 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. | ||
| CVE-2023-33055 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory Corruption in Audio while invoking callback function in driver from ADSP. | ||
| CVE-2023-33031 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | ||
| CVE-2023-33035 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory corruption while invoking callback function of AFE from ADSP. | ||
| CVE-2023-33034 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory corruption while parsing the ADSP response command. | ||
| CVE-2023-24850 | Hig | 0.51 | 7.8 | 0.00 | Oct 3, 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | ||
| CVE-2023-28573 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing WMI command parameters. | ||
| CVE-2023-28567 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28565 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | ||
| CVE-2023-28564 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. | ||
| CVE-2023-28560 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | ||
| CVE-2023-28559 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28558 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN handler while processing PhyID in Tx status handler. | ||
| CVE-2023-28557 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | ||
| CVE-2023-28549 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. | ||
| CVE-2023-28548 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | ||
| CVE-2023-28544 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers. | ||
| CVE-2023-21664 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory Corruption in Core Platform while printing the response buffer in log. | ||
| CVE-2023-21662 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in Core Platform while printing the response buffer in log. | ||
| CVE-2023-28542 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while fetching TX status information. | ||
| CVE-2023-28541 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | ||
| CVE-2023-24854 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. | ||
| CVE-2023-24851 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while parsing QMI response message from firmware. | ||
| CVE-2023-22387 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | ||
| CVE-2023-22386 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. | ||
| CVE-2023-21670 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. | ||
| CVE-2023-21657 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memoru corruption in Audio when ADSP sends input during record use case. | ||
| CVE-2023-21656 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. | ||
| CVE-2022-33264 | Hig | 0.51 | 7.9 | 0.00 | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | ||
| CVE-2022-33292 | Hig | 0.51 | 7.8 | 0.00 | May 2, 2023 | Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it. | ||
| CVE-2022-25713 | Hig | 0.51 | 7.8 | 0.00 | May 2, 2023 | Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key. | ||
| CVE-2022-33278 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. | ||
| CVE-2022-33242 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. | ||
| CVE-2022-25705 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response | ||
| CVE-2022-33248 | Hig | 0.51 | 7.8 | 0.00 | Feb 12, 2023 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. | ||
| CVE-2022-33233 | Hig | 0.51 | 7.8 | 0.00 | Feb 12, 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. | ||
| CVE-2022-33217 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2022 | Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile | ||
| CVE-2022-25660 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2022 | Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-22094 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-22093 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-22092 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | Memory corruption in kernel due to use after free issue in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-22070 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2022 | Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2022-22061 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2022 | Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile | ||
| CVE-2022-22103 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto | ||
| CVE-2022-22072 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2021-35129 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure… | ||
| CVE-2021-35102 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile | ||
| CVE-2021-35094 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-35072 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in SPS Application while exporting public key in sorter TA.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Audio while processing the VOC packet data from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Audio while invoking callback function in driver from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking callback function of AFE from ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while parsing the ADSP response command.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing WMI command parameters.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Core Platform while printing the response buffer in log.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Core Platform while printing the response buffer in log.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while fetching TX status information.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
- risk 0.51cvss 7.8epss 0.00
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- risk 0.51cvss 7.8epss 0.00
Memoru corruption in Audio when ADSP sends input during record use case.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- risk 0.51cvss 7.9epss 0.00
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
- risk 0.51cvss 7.8epss 0.00
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption in kernel due to use after free issue in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.51cvss 7.8epss 0.00
Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto
- risk 0.51cvss 7.8epss 0.00
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.51cvss 7.8epss 0.00
Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure…
- risk 0.51cvss 7.8epss 0.00
Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.00
Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Page 26 of 61