VYPR

Vendor CVEs

Qualcomm

All CVEs

3,001 total · sorted by risk
  • CVE-2025-59601MedJun 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.

  • CVE-2026-43347HigMay 8, 2026
    risk 0.42cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: monaco: Reserve full Gunyah metadata region We observe spurious "Synchronous External Abort" exceptions (ESR=0x96000010) and kernel crashes on Monaco-based platforms. These faults are caused…

  • CVE-2025-47404MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

  • CVE-2025-47403MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

  • CVE-2025-47401MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing target power rate tables during channel configuration.

  • CVE-2025-47374MedApr 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.

  • CVE-2025-47384MedMar 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when MAC configures config id greater than supported maximum value.

  • CVE-2025-47371MedMar 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when an LTE RLC packet with invalid TB is received by UE.

  • CVE-2025-47402MedFeb 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a received frame with an excessively large authentication information element.

  • CVE-2025-47395MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

  • CVE-2025-47325MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing system calls with invalid parameters.

  • CVE-2025-47370MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

  • CVE-2025-27040MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure may occur while processing the hypervisor log.

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2024-45556MedApr 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.

  • CVE-2024-23350MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.

  • CVE-2024-21467MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling beacon probe frame during scan entry generation in client side.

  • CVE-2024-21459MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling beacon or probe response frame in STA.

  • CVE-2024-21466MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while parsing sub-IE length during new IE generation.

  • CVE-2024-21458MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling SA query action frame.

  • CVE-2024-21457MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    INformation disclosure while handling Multi-link IE in beacon frame.

  • CVE-2024-21456MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure while parsing beacon frame in STA.

  • CVE-2023-43537MedJun 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling T2LM Action Frame in WLAN Host.

  • CVE-2023-21667MedSep 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.

  • CVE-2023-28576MedAug 8, 2023
    risk 0.42cvss 6.4epss 0.00

    The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.…

  • CVE-2023-21647MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.00

    Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

  • CVE-2022-25674MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.00

    Cryptographic issues in WLAN during the group key handshake of the WPA/WPA2 protocol in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2022-31884MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.

  • CVE-2021-35080MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35070MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30346MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30345MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-35093MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service in BlueCore

  • CVE-2021-30348MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2021-1918MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1960MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2021-1957MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-1956MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11266MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11230MedMar 17, 2021
    risk 0.42cvss 6.4epss 0.00

    Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11220MedMar 17, 2021
    risk 0.42cvss 6.4epss 0.00

    While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT,…

  • CVE-2020-11152MedJan 21, 2021
    risk 0.42cvss 6.4epss 0.00

    Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2020-11151MedJan 21, 2021
    risk 0.42cvss 6.4epss 0.00

    Race condition occurs while calling user space ioctl from two different threads can results to use after free issue in video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2020-3702MedSep 8, 2020
    risk 0.42cvss 6.5epss 0.00

    u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute,…

  • CVE-2019-10504MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    Firmware not able to send EXT scan response to host within 1 sec due to resource consumption issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, Qualcomm 215, SD…

  • CVE-2017-15835MedDec 7, 2018
    risk 0.42cvss 6.5epss 0.00

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop may potentially occur resulting in a…

  • CVE-2018-5916MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.00

    Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD…

  • CVE-2017-18283MedOct 23, 2018
    risk 0.42cvss 6.5epss 0.01

    Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 625, SD 835, SD 845, SD 850, SDA660.

  • CVE-2018-5871MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.00

    In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630,…

Page 53 of 61