VYPR

Vendor CVEs

Qualcomm

All CVEs

3,001 total · sorted by risk
  • CVE-2016-2474HigJun 13, 2016
    risk 0.51cvss 7.8epss 0.01

    The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 27424603.

  • CVE-2016-2066HigJun 13, 2016
    risk 0.51cvss 7.8epss 0.01

    Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via a…

  • CVE-2016-2061HigJun 13, 2016
    risk 0.51cvss 7.8epss 0.01

    Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory…

  • CVE-2016-2432HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.

  • CVE-2016-2060HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access…

  • CVE-2015-0571HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.01

    The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows attackers to gain privileges via a crafted…

  • CVE-2015-0570HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow in the SET_WPS_IE IOCTL implementation in wlan_hdd_hostapd.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to…

  • CVE-2016-2062HigMay 5, 2016
    risk 0.51cvss 7.8epss 0.00

    The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type,…

  • CVE-2024-45549HigApr 7, 2025
    risk 0.50cvss 7.7epss 0.00

    Information disclosure while creating MQ channels.

  • CVE-2023-21652HigAug 8, 2023
    risk 0.50cvss 7.7epss 0.00

    Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

  • CVE-2022-22069HigSep 2, 2022
    risk 0.50cvss 7.7epss 0.00

    Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35116HigJun 14, 2022
    risk 0.50cvss 7.7epss 0.00

    APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2020-25858HigOct 15, 2020
    risk 0.50cvss 7.5epss 0.10

    The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the…

  • CVE-2018-11259HigJul 6, 2018
    risk 0.50cvss 7.7epss 0.00

    Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure world full read/write access to the partition until the…

  • CVE-2026-25292HigAug 4, 2026
    risk 0.49cvss 7.6epss 0.00

    Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

  • CVE-2026-24084HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

  • CVE-2026-21381HigApr 6, 2026
    risk 0.49cvss 7.6epss 0.00

    Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

  • CVE-2026-21367HigApr 6, 2026
    risk 0.49cvss 7.6epss 0.00

    Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

  • CVE-2025-24857HigDec 10, 2025
    risk 0.49cvss 7.6epss 0.00

    Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

  • CVE-2025-47328HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing power control requests with invalid antenna or stream values.

  • CVE-2025-47326HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while handling command data during power control processing.

  • CVE-2025-47318HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the EPTM test control message to get the test pattern.

  • CVE-2025-47324HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

  • CVE-2025-27073HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while creating NDP instance.

  • CVE-2025-27066HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing an ANQP message.

  • CVE-2025-27065HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a frame with malformed shared-key descriptor.

  • CVE-2025-21477HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing CCCH data when NW sends data with invalid length.

  • CVE-2025-21452HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

  • CVE-2025-27057HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while handling beacon frames with invalid IE header length.

  • CVE-2025-21454HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing received beacon frame.

  • CVE-2025-21449HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while processing malformed length field in SSID IEs.

  • CVE-2025-21446HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.

  • CVE-2025-27029HigJun 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

  • CVE-2025-21463HigJun 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the EHT operation IE in the received beacon frame.

  • CVE-2025-21459HigMay 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing per STA profile in ML IE.

  • CVE-2024-49847HigMay 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.

  • CVE-2025-21448HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing SSID in action frames.

  • CVE-2025-21435HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing extended IE in beacon.

  • CVE-2025-21434HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing EHT operation IE or EHT capability IE.

  • CVE-2025-21430HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

  • CVE-2025-21429HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

  • CVE-2025-21428HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

  • CVE-2024-33058HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

  • CVE-2024-53027HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while processing the country IE.

  • CVE-2024-38404HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.

  • CVE-2024-45558HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

  • CVE-2024-43064HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

  • CVE-2024-33063HigDec 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.

  • CVE-2024-38405HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the CU information from RNR IE.

  • CVE-2024-38403HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing BTM ML IE when per STA profile is not included.

Page 38 of 61