Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-2474 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2016 | The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 27424603. | ||
| CVE-2016-2066 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2016 | Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via a… | ||
| CVE-2016-2061 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2016 | Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory… | ||
| CVE-2016-2432 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2016 | The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059. | ||
| CVE-2016-2060 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2016 | server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access… | ||
| CVE-2015-0571 | Hig | 0.51 | 7.8 | 0.01 | May 9, 2016 | The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to gain privileges via a crafted… | ||
| CVE-2015-0570 | Hig | 0.51 | 7.8 | 0.02 | May 9, 2016 | Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to… | ||
| CVE-2016-2062 | Hig | 0.51 | 7.8 | 0.00 | May 5, 2016 | The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type,… | ||
| CVE-2024-45549 | Hig | 0.50 | 7.7 | 0.00 | Apr 7, 2025 | Information disclosure while creating MQ channels. | ||
| CVE-2023-21652 | Hig | 0.50 | 7.7 | 0.00 | Aug 8, 2023 | Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use. | ||
| CVE-2022-22069 | Hig | 0.50 | 7.7 | 0.00 | Sep 2, 2022 | Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2021-35116 | Hig | 0.50 | 7.7 | 0.00 | Jun 14, 2022 | APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2020-25858 | Hig | 0.50 | 7.5 | 0.10 | Oct 15, 2020 | The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the… | ||
| CVE-2018-11259 | Hig | 0.50 | 7.7 | 0.00 | Jul 6, 2018 | Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the… | ||
| CVE-2026-25292 | Hig | 0.49 | 7.6 | 0.00 | Aug 4, 2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | ||
| CVE-2026-24084 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2026-21367 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | ||
| CVE-2025-24857 | Hig | 0.49 | 7.6 | 0.00 | Dec 10, 2025 | Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code. | ||
| CVE-2025-47328 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while processing power control requests with invalid antenna or stream values. | ||
| CVE-2025-47326 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while handling command data during power control processing. | ||
| CVE-2025-47318 | Hig | 0.49 | 7.5 | 0.00 | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. | ||
| CVE-2025-47324 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Information disclosure while accessing and modifying the PIB file of a remote device via powerline. | ||
| CVE-2025-27073 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while creating NDP instance. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-27065 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a frame with malformed shared-key descriptor. | ||
| CVE-2025-21477 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing CCCH data when NW sends data with invalid length. | ||
| CVE-2025-21452 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. | ||
| CVE-2025-27057 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while handling beacon frames with invalid IE header length. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21449 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. | ||
| CVE-2025-21446 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | ||
| CVE-2025-27029 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | ||
| CVE-2025-21463 | Hig | 0.49 | 7.5 | 0.00 | Jun 3, 2025 | Transient DOS while processing the EHT operation IE in the received beacon frame. | ||
| CVE-2025-21459 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while parsing per STA profile in ML IE. | ||
| CVE-2024-49847 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2025-21435 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. | ||
| CVE-2025-21434 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing EHT operation IE or EHT capability IE. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2025-21429 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | ||
| CVE-2025-21428 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | ||
| CVE-2024-33058 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-38404 | Hig | 0.49 | 7.5 | 0.00 | Feb 3, 2025 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. | ||
| CVE-2024-45558 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | ||
| CVE-2024-43064 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | ||
| CVE-2024-33063 | Hig | 0.49 | 7.5 | 0.00 | Dec 2, 2024 | Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. | ||
| CVE-2024-38405 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS while processing the CU information from RNR IE. | ||
| CVE-2024-38403 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS while parsing BTM ML IE when per STA profile is not included. |
- risk 0.51cvss 7.8epss 0.01
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 27424603.
- risk 0.51cvss 7.8epss 0.01
Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via a…
- risk 0.51cvss 7.8epss 0.01
Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory…
- risk 0.51cvss 7.8epss 0.00
The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.
- risk 0.51cvss 7.8epss 0.00
server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access…
- risk 0.51cvss 7.8epss 0.01
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to gain privileges via a crafted…
- risk 0.51cvss 7.8epss 0.02
Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to…
- risk 0.51cvss 7.8epss 0.00
The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type,…
- risk 0.50cvss 7.7epss 0.00
Information disclosure while creating MQ channels.
- risk 0.50cvss 7.7epss 0.00
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
- risk 0.50cvss 7.7epss 0.00
Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.50cvss 7.7epss 0.00
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.50cvss 7.5epss 0.10
The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the…
- risk 0.50cvss 7.7epss 0.00
Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the…
- risk 0.49cvss 7.6epss 0.00
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
- risk 0.49cvss 7.5epss 0.00
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- risk 0.49cvss 7.6epss 0.00
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing power control requests with invalid antenna or stream values.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling command data during power control processing.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the EPTM test control message to get the test pattern.
- risk 0.49cvss 7.5epss 0.00
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while creating NDP instance.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a frame with malformed shared-key descriptor.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing CCCH data when NW sends data with invalid length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while handling beacon frames with invalid IE header length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing malformed length field in SSID IEs.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the EHT operation IE in the received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing per STA profile in ML IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing extended IE in beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
- risk 0.49cvss 7.5epss 0.00
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- risk 0.49cvss 7.5epss 0.00
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the CU information from RNR IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Page 38 of 61