Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 10/50
8.2
CVE-2024-33064

Information disclosure while parsing the multiple MBSSID IEs from the beacon.

7.5
CVE-2024-33049

Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

6.7
CVE-2024-23379

Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

6.7
CVE-2024-23378

Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.

6.7
CVE-2024-23376

Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IO

6.7
CVE-2024-23375

Memory corruption during the network scan request.

6.7
CVE-2024-23374

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to

6.7
CVE-2024-23370

Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process

7.8
CVE-2024-23369

Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

7.8
CVE-2024-21455

Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

7.8
CVE-2024-38402

Memory corruption while processing IOCTL call for getting group info.

7.8
CVE-2024-38401

Memory corruption while processing concurrent IOCTL calls.

8.4
CVE-2024-33060

Memory corruption when two threads try to map and unmap a single node simultaneously.

7.5
CVE-2024-33057

Transient DOS while parsing the multi-link element Control field when common information length check is missing before

7.8
CVE-2024-33054

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

7.8
CVE-2024-33052

Memory corruption when user provides data for FM HCI command control operations.

7.5
CVE-2024-33051

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

7.5
CVE-2024-33050

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing

7.5
CVE-2024-33048

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

8.4
CVE-2024-33047

Memory corruption when the captureRead QDCM command is invoked from user-space.

8.4
CVE-2024-33045

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

5.5
CVE-2024-33043

Transient DOS while handling PS event when Program Service name length offset value is set to 255.

7.8
CVE-2024-33042

Memory corruption when Alternative Frequency offset value is set to 255.

7.8
CVE-2024-33038

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

8.4
CVE-2024-33035

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

6.8
CVE-2024-33016

memory corruption when an invalid firehose patch command is invoked.

8.4
CVE-2024-23365

Memory corruption while releasing shared resources in MinkSocket listener thread.

7.5
CVE-2024-23364

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme

7.1
CVE-2024-23362

Cryptographic issue while parsing RSA keys in COBR format.

8.2
CVE-2024-23359

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

7.5
CVE-2024-23358

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

8.4
CVE-2024-33034

Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaimi

8.4
CVE-2024-33028

Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

8.4
CVE-2024-33027

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corruptin

7.5
CVE-2024-33026

Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of

7.5
CVE-2024-33025

Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

7.5
CVE-2024-33024

Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the M

8.4
CVE-2024-33023

Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

8.4
CVE-2024-33022

Memory corruption while allocating memory in HGSL driver.

8.4
CVE-2024-33021

Memory corruption while processing IOCTL call to set metainfo.

7.5
CVE-2024-33020

Transient DOS while processing TID-to-link mapping IE elements.

7.5
CVE-2024-33019

Transient DOS while parsing the received TID-to-link mapping action frame.

7.5
CVE-2024-33018

Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

7.5
CVE-2024-33015

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is les

7.5
CVE-2024-33014

Transient DOS while parsing ESP IE from beacon/probe response frame.

7.5
CVE-2024-33013

Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

7.5
CVE-2024-33012

Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end

7.5
CVE-2024-33011

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

7.5
CVE-2024-33010

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

8.4
CVE-2024-23384

Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started