VYPR

Vendor CVEs

Qualcomm

All CVEs

3,013 total · sorted by risk
  • CVE-2021-35118MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35098MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35092MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-30325MedFeb 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-30324MedFeb 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30313MedJan 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30298MedJan 3, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access due to improper validation of item size and DIAG memory pools data while switching between USB and PCIE interface in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30266MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30265MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible memory corruption due to improper validation of memory address while processing user-space IOCTL for clearing Filter and Route statistics in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2021-30264MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-30263MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible race condition can occur due to lack of synchronization mechanism when On-Device Logging node open twice concurrently in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-1966MedOct 20, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible buffer overflow due to lack of length check of source and destination buffer before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-1963MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-1962MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Buffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for input maximum endpoint pair and its size in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,…

  • CVE-2021-1961MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1958MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    A race condition in fastrpc kernel driver for dynamic process creation can lead to use after free scenario in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-1931MedJul 13, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2020-11160MedJun 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Resource leakage issue during dci client registration due to reference count is not decremented if dci client registration fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-1895MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11295MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11231MedApr 7, 2021
    risk 0.44cvss 6.7epss 0.00

    Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11308MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2020-11305MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11286MedFeb 22, 2021
    risk 0.44cvss 6.8epss 0.00

    An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11198MedFeb 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2020-11147MedFeb 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11183MedJan 21, 2021
    risk 0.44cvss 6.7epss 0.00

    A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2020-11150MedJan 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2020-11149MedJan 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Out of bound access due to usage of an out-of-range pointer offset in the camera driver. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-11148MedJan 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggered and callback instance is deleted in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2020-25859MedOct 15, 2020
    risk 0.44cvss 6.7epss 0.00

    The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the input, while handling a SetGatewayUrl() request. A local attacker with shell access can pass shell metacharacters and run arbitrary…

  • CVE-2016-10443MedApr 18, 2018
    risk 0.44cvss 6.8epss 0.01

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD…

  • CVE-2025-47333MedJan 7, 2026
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling buffer mapping operations in the cryptographic driver.

  • CVE-2025-27039MedOct 9, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

  • CVE-2025-21426MedJul 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing camera TPG write request.

  • CVE-2024-53018MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption may occur while processing the OIS packet parser.

  • CVE-2024-53017MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling test pattern generator IOCTL command.

  • CVE-2024-53016MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing I2C settings in Camera driver.

  • CVE-2024-53015MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing IOCTL command to handle buffers associated with a session.

  • CVE-2024-53013MedJun 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption may occur while processing voice call registration with user.

  • CVE-2024-49830MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing an IOCTL call to set mixer controls.

  • CVE-2024-45583MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

  • CVE-2024-45581MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while sound model registration for voice activation with audio kernel driver.

  • CVE-2024-45570MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption may occur during IO configuration processing when the IO port count is invalid.

  • CVE-2024-45563MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

  • CVE-2024-45562MedMay 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption during concurrent access to server info object due to unprotected critical field.

  • CVE-2024-45544MedApr 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing IOCTL calls to add route entry in the HW.

  • CVE-2024-45543MedApr 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while accessing MSM channel map and mixer functions.

  • CVE-2024-45540MedApr 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while invoking IOCTL map buffer request from userspace.

  • CVE-2024-38413MedFeb 3, 2025
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while processing frame packets.

Page 52 of 61