VYPR

Vendor CVEs

Qualcomm

All CVEs

3,001 total · sorted by risk
  • CVE-2014-10062HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD…

  • CVE-2014-10058HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 845, and Snapdragon_High_Med_2016, unauthorized users can potentially modify…

  • CVE-2014-10055HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected contents if HLOS doesn't request for security restoration for OCMEM xPU's.

  • CVE-2014-10047HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption key to crypto engine, information leak could occur.

  • CVE-2014-10044HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 210/SD 212/SD 205, SD 400, SD 617, SD 800, and SD 820, in the time daemon, unauthorized users can potentially modify system time and cause an array index to…

  • CVE-2014-10043HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure…

  • CVE-2017-18143HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, on a secure device, PD dumps are collected when debugging is not enabled.

  • CVE-2017-18128HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, improper access control while configuring MPU protecting error correction registers may potentially lead to exposure of related secured data.

  • CVE-2017-18126HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA6174A, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD…

  • CVE-2017-18125HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, when secure camera is activated it stores captured data in protected buffers. The TEE application which…

  • CVE-2017-18073HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

  • CVE-2017-18072HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427,…

  • CVE-2016-8486HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823691.

  • CVE-2016-8485HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.

  • CVE-2016-10235HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#1046409.

  • CVE-2018-3598HigApr 3, 2018
    risk 0.49cvss 7.5epss 0.00

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, insufficient validation of parameters from userspace in the camera driver can lead to information leak and…

  • CVE-2018-3584HigApr 3, 2018
    risk 0.49cvss 7.5epss 0.00

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a Use After Free condition can occur in the function rmnet_usb_ctrl_init().

  • CVE-2017-14875HigMar 30, 2018
    risk 0.49cvss 7.5epss 0.01

    In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.

  • CVE-2017-18059HigMar 16, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_scan_event_callback(), which is received from firmware, leads to potential out of bounds memory read.

  • CVE-2017-18053HigMar 16, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for fix_param->vdev_id in wma_p2p_lo_event_handler(), which is received from firmware, leads to potential out of bounds memory read.

  • CVE-2017-18052HigMar 16, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for cmpl_params->num_reports, param_buf->desc_ids and param_buf->status in wma_mgmt_tx_bundle_completion_handler(), which is received from…

  • CVE-2017-14878HigMar 15, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be exceeded resulting in a denial of service.

  • CVE-2006-6025HigNov 21, 2006
    risk 0.49cvss 7.5epss 0.01

    QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. As of 20061118, this…

  • CVE-2026-25288HigAug 4, 2026
    risk 0.48cvss 7.4epss 0.00

    Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

  • CVE-2023-22382HigOct 3, 2023
    risk 0.48cvss 7.4epss 0.00

    Weak configuration in Automotive while VM is processing a listener request from TEE.

  • CVE-2020-11277HigFeb 22, 2021
    risk 0.48cvss 7.4epss 0.00

    Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2026-24092HigJun 1, 2026
    risk 0.47cvss 7.2epss 0.00

    Memory Corruption when processing fastboot commands to set display mode.

  • CVE-2026-24091HigJun 1, 2026
    risk 0.47cvss 7.2epss 0.00

    Memory corruption while processing fastboot commands with improperly formatted input.

  • CVE-2026-24089HigJun 1, 2026
    risk 0.47cvss 7.2epss 0.00

    Memory corruption while processing fastboot commands with invalid input.

  • CVE-2026-24087HigJun 1, 2026
    risk 0.47cvss 7.2epss 0.00

    Memory corruption while processing fastboot OEM commands.

  • CVE-2026-24085HigJun 1, 2026
    risk 0.47cvss 7.2epss 0.00

    Memory Corruption when processing display command line information due to improper initialization of a variable.

  • CVE-2025-47383HigMar 2, 2026
    risk 0.47cvss 7.2epss 0.00

    Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

  • CVE-2025-27071HigAug 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while processing specific files in Powerline Communication Firmware.

  • CVE-2025-21425HigApr 7, 2025
    risk 0.47cvss 7.3epss 0.00

    Memory corruption may occur due top improper access control in HAB process.

  • CVE-2024-21469HigJul 1, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

  • CVE-2024-21480HigMay 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while playing audio file having large-sized input buffer.

  • CVE-2024-21463HigApr 1, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while processing Codec2 during v13k decoder pitch synthesis.

  • CVE-2024-21452HigApr 1, 2024
    risk 0.47cvss 7.3epss 0.00

    Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.

  • CVE-2023-43548HigMar 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption while parsing qcp clip with invalid chunk data size.

  • CVE-2023-43519HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

  • CVE-2023-43518HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video while parsing invalid mp2 clip.

  • CVE-2022-33273HigMay 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.

  • CVE-2022-40537HigMar 10, 2023
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.

  • CVE-2022-40515HigMar 10, 2023
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.

  • CVE-2022-33280HigFeb 12, 2023
    risk 0.47cvss 7.3epss 0.00

    Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

  • CVE-2022-33265HigJan 9, 2023
    risk 0.47cvss 7.3epss 0.00

    Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a single, unassociated device.

  • CVE-2022-33234HigNov 15, 2022
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-25687HigOct 19, 2022
    risk 0.47cvss 7.3epss 0.00

    memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2022-25688HigSep 16, 2022
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2022-25686HigSep 16, 2022
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

Page 45 of 61