Vendor CVEs
Qualcomm
All CVEs
3,001 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-8481 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8480 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a… | ||
| CVE-2016-8476 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8421 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8420 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8419 | Hig | 0.46 | 7.0 | 0.01 | Feb 8, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8452 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8450 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8444 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8434 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may… | ||
| CVE-2016-8415 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8412 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8392 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-8391 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-6791 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-6755 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2017 | An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.… | ||
| CVE-2016-2443 | Hig | 0.46 | 7.0 | 0.00 | May 9, 2016 | The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525. | ||
| CVE-2016-2442 | Hig | 0.46 | 7.0 | 0.00 | May 9, 2016 | The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26494907. | ||
| CVE-2016-2441 | Hig | 0.46 | 7.0 | 0.00 | May 9, 2016 | The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26354602. | ||
| CVE-2016-2059 | Hig | 0.46 | 7.0 | 0.00 | May 5, 2016 | The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a… | ||
| CVE-2022-31886 | Med | 0.45 | 6.5 | 0.02 | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form. | ||
| CVE-2026-24076 | Med | 0.44 | 6.7 | 0.00 | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | ||
| CVE-2025-59614 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when sending random number generator command with insufficient output buffer size. | ||
| CVE-2025-59613 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory Corruption when output buffer size is smaller than input buffer size during data copying operation. | ||
| CVE-2025-59612 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory corruption in windows drivers while sending incorrect trusted application request | ||
| CVE-2025-59611 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation | ||
| CVE-2025-47364 | Med | 0.44 | 6.8 | 0.00 | Feb 2, 2026 | Memory corruption while calculating offset from partition start point. | ||
| CVE-2025-47363 | Med | 0.44 | 6.8 | 0.00 | Feb 2, 2026 | Memory corruption when calculating oversized partition sizes without proper checks. | ||
| CVE-2025-47344 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while handling sensor utility operations. | ||
| CVE-2025-47337 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while accessing a synchronization object during concurrent operations. | ||
| CVE-2025-47336 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while performing sensor register read operations. | ||
| CVE-2025-47335 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while parsing clock configuration data for a specific hardware type. | ||
| CVE-2025-47334 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. | ||
| CVE-2025-47332 | Med | 0.44 | 6.7 | 0.00 | Jan 7, 2026 | Memory corruption while processing a config call from userspace. | ||
| CVE-2025-47319 | Med | 0.44 | 6.7 | 0.00 | Dec 18, 2025 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | ||
| CVE-2024-49829 | Med | 0.44 | 6.7 | 0.00 | May 6, 2025 | Memory corruption can occur during context user dumps due to inadequate checks on buffer length. | ||
| CVE-2024-45568 | Med | 0.44 | 6.7 | 0.00 | May 6, 2025 | Memory corruption due to improper bounds check while command handling in camera-kernel driver. | ||
| CVE-2024-49848 | Med | 0.44 | 6.7 | 0.00 | Apr 7, 2025 | Memory corruption while processing multiple IOCTL calls from HLOS to DSP. | ||
| CVE-2024-33061 | Med | 0.44 | 6.8 | 0.00 | Jan 6, 2025 | Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process. | ||
| CVE-2024-33059 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption while processing frame command IOCTL calls. | ||
| CVE-2024-33055 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption while invoking IOCTL calls to unmap the DMA buffers. | ||
| CVE-2024-33041 | Med | 0.44 | 6.7 | 0.00 | Jan 6, 2025 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | ||
| CVE-2024-33053 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when multiple threads try to unregister the CVP buffer at the same time. | ||
| CVE-2024-33040 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access. | ||
| CVE-2024-33039 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service. | ||
| CVE-2024-33036 | Med | 0.44 | 6.7 | 0.00 | Dec 2, 2024 | Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. | ||
| CVE-2021-30299 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. | ||
| CVE-2017-9711 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2024 | Certain unprivileged processes are able to perform IOCTL calls. | ||
| CVE-2024-33033 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption while processing IOCTL calls to unmap the buffers. | ||
| CVE-2024-33032 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2024 | Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. |
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…
- risk 0.46cvss 7.0epss 0.00
The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.
- risk 0.46cvss 7.0epss 0.00
The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26494907.
- risk 0.46cvss 7.0epss 0.00
The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26354602.
- risk 0.46cvss 7.0epss 0.00
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a…
- risk 0.45cvss 6.5epss 0.02
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when processing registry values with incorrect types using a direct query method.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when sending random number generator command with insufficient output buffer size.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in windows drivers while sending incorrect trusted application request
- risk 0.44cvss 6.7epss 0.00
Memory corruption in diagnostic services due to absence of input validation
- risk 0.44cvss 6.8epss 0.00
Memory corruption while calculating offset from partition start point.
- risk 0.44cvss 6.8epss 0.00
Memory corruption when calculating oversized partition sizes without proper checks.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while handling sensor utility operations.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while accessing a synchronization object during concurrent operations.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while performing sensor register read operations.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing clock configuration data for a specific hardware type.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing a config call from userspace.
- risk 0.44cvss 6.7epss 0.00
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
- risk 0.44cvss 6.7epss 0.00
Memory corruption can occur during context user dumps due to inadequate checks on buffer length.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
- risk 0.44cvss 6.8epss 0.00
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing frame command IOCTL calls.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
- risk 0.44cvss 6.7epss 0.00
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
- risk 0.44cvss 6.7epss 0.00
Possible out of bound access in audio module due to lack of validation of user provided input.
- risk 0.44cvss 6.7epss 0.00
Certain unprivileged processes are able to perform IOCTL calls.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while processing IOCTL calls to unmap the buffers.
- risk 0.44cvss 6.7epss 0.00
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Page 49 of 61