Qualcomm
46,786 known vulnerabilities
Top Products
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length o
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto,
Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snap
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdr
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdrago
Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Aut
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon In
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Aut
Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapd
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, S
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer l
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdrago
Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, S
Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in S
Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the me
Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdra
Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon
Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null poi
Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of servi
Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid
Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Comput
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is f
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Sna
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Sn
Out of bound memory read while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute,
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapd
Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Au
RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to captu
Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before access
Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of servic
When sending a socket event message to a user application, invalid information will be passed if socket is freed by othe
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in tu
Possible memory corruption in RPM region due to improper XPU configuration in Snapdragon Connectivity, Snapdragon Indust
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in S
Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in
Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Indus
Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdrago
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes
Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapd
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer i
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapd
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be inval
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started