Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

2,286 known vulnerabilities

2
CRITICAL
76
HIGH
39
MEDIUM

Top Products

fastconnect 6900 firmware 55 fastconnect 6900 55 fastconnect 7800 firmware 54 fastconnect 7800 54 fastconnect 6700 firmware 43 fastconnect 6700 43 fastconnect 6200 firmware 34 fastconnect 6200 34 cologne firmware 28 cologne 28
117 CVEs · Page 2/3
7.8
CVE-2025-47405

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

6.5
CVE-2025-47404

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modif

6.5
CVE-2025-47403

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles

6.5
CVE-2025-47401

Transient DOS when processing target power rate tables during channel configuration.

7.8
CVE-2026-21382

Memory Corruption when handling power management requests with improperly sized input/output buffers.

7.6
CVE-2026-21381

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware

7.8
CVE-2026-21380

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

7.8
CVE-2026-21378

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-21376

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-21375

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21374

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio

7.8
CVE-2026-21373

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21372

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

7.8
CVE-2026-21371

Memory Corruption when retrieving output buffer with insufficient size validation.

7.6
CVE-2026-21367

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

7.1
CVE-2025-47400

Cryptographic issue while copying data to a destination buffer without validating its size.

8.8
CVE-2025-47392

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

7.8
CVE-2025-47391

Memory corruption while processing a frame request from user.

7.8
CVE-2025-47390

Memory corruption while preprocessing IOCTL request in JPEG driver.

7.8
CVE-2025-47389

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

6.5
CVE-2025-47374

Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.

7.8
CVE-2026-21385 KEV

Memory corruption while using alignments for memory allocation.

7.8
CVE-2025-59603

Memory Corruption when processing invalid user address with nonstandard buffer address.

7.8
CVE-2025-59600

Memory Corruption when adding user-supplied data without checking available buffer space.

7.8
CVE-2025-47386

Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.

7.8
CVE-2025-47385

Memory Corruption when accessing trusted execution environment without proper privilege check.

6.5
CVE-2025-47384

Transient DOS when MAC configures config id greater than supported maximum value.

7.2
CVE-2025-47383

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

7.8
CVE-2025-47381

Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.

7.8
CVE-2025-47379

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and

7.1
CVE-2025-47378

Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

7.8
CVE-2025-47377

Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.

7.8
CVE-2025-47376

Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.

7.8
CVE-2025-47375

Memory corruption while handling different IOCTL calls from the user-space simultaneously.

7.8
CVE-2025-47373

Memory Corruption when accessing buffers with invalid length during TA invocation.

6.5
CVE-2025-47371

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

6.5
CVE-2025-47402

Transient DOS when processing a received frame with an excessively large authentication information element.

7.8
CVE-2025-47399

Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.

7.8
CVE-2025-47398

Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers

7.8
CVE-2025-47397

Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.

7.1
CVE-2025-47366

Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.

6.8
CVE-2025-47364

Memory corruption while calculating offset from partition start point.

6.8
CVE-2025-47363

Memory corruption when calculating oversized partition sizes without proper checks.

7.8
CVE-2025-47359

Memory Corruption when multiple threads simultaneously access a memory free API.

7.8
CVE-2025-47358

Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad

7.8
CVE-2025-47396

Memory corruption occurs when a secure application is launched on a device with insufficient memory.

6.5
CVE-2025-47395

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

7.8
CVE-2025-47394

Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

7.8
CVE-2025-47393

Memory corruption when accessing resources in kernel driver.

7.8
CVE-2025-47388

Memory corruption while passing pages to DSP with an unaligned starting address.

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 2,286 CVE records in our database, including 22 critical and 1506 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 22 critical severity (CVSS 9.0+) and 1506 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started