Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

14,688 known vulnerabilities

295
CRITICAL
388
HIGH
108
MEDIUM

Top Products

mdm9206 firmware 420 mdm9206 420 mdm9607 firmware 404 mdm9607 404 mdm9650 firmware 391 mdm9650 391 sd 210 firmware 330 sd 210 329 msm8909w firmware 297 msm8909w 297
791 CVEs · Page 3/16
7.8
CVE-2025-47380

Memory corruption while preprocessing IOCTLs in sensors.

5.5
CVE-2025-47369

Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses

7.8
CVE-2025-47356

Memory Corruption when multiple threads concurrently access and modify shared resources.

7.8
CVE-2025-47348

Memory corruption while processing identity credential operations in the trusted application.

7.8
CVE-2025-47346

Memory corruption while processing a secure logging command in the trusted application.

8.4
CVE-2025-47345

Cryptographic issue may occur while encrypting license data.

6.7
CVE-2025-47344

Memory corruption while handling sensor utility operations.

7.8
CVE-2025-47343

Memory corruption while processing a video session to set video parameters.

7.8
CVE-2025-47339

Memory corruption while deinitializing a HDCP session.

6.7
CVE-2025-47337

Memory corruption while accessing a synchronization object during concurrent operations.

6.7
CVE-2025-47336

Memory corruption while performing sensor register read operations.

6.7
CVE-2025-47335

Memory corruption while parsing clock configuration data for a specific hardware type.

6.7
CVE-2025-47334

Memory corruption while processing shared command buffer packet between camera userspace and kernel.

6.6
CVE-2025-47333

Memory corruption while handling buffer mapping operations in the cryptographic driver.

6.7
CVE-2025-47332

Memory corruption while processing a config call from userspace.

6.1
CVE-2025-47331

Information disclosure while processing a firmware event.

5.5
CVE-2025-47330

Transient DOS while parsing video packets received from the video firmware.

7.8
CVE-2019-2304

Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon A

7.8
CVE-2019-2274

Improper Access Control for RPU write access from secure processor in Snapdragon Auto, Snapdragon Compute, Snapdragon Co

9.8
CVE-2019-2242

Device memory may get corrupted because of buffer overflow/underflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon

9.8
CVE-2019-10614

Out of boundary access is possible as there is no validation of data accessed against the received size of the packet in

7.8
CVE-2019-10607

Out of bounds memcpy can occur by providing the embedded NULL character string and length greater than the actual string

7.8
CVE-2019-10605

Buffer overwrite can occur in IEEE80211 header filling function due to lack of range check of array index received from

7.8
CVE-2019-10601

Out of bound access can occur while processing firmware event due to lack of validation of WMI message received from fir

7.8
CVE-2019-10600

Use of local variable as argument to netlink CB callback goes out of it scope when callback triggered lead to invalid st

7.8
CVE-2019-10598

Out of bound access can occur while processing peer info in IBSS connection mode due to lack of upper bounds check to en

7.8
CVE-2019-10595

Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received fro

7.8
CVE-2019-10584

Possibility of out of bound access in debug queue, if packet size field is corrupted in Snapdragon Auto, Snapdragon Comp

9.8
CVE-2019-10572

Improper check in video driver while processing data from video firmware can lead to integer overflow and then buffer ov

7.8
CVE-2019-10564

Possible OOB issue in EEPROM due to lack of check while accessing memory map array at the time of reading operation in S

9.8
CVE-2019-10557

Out-of-bound read in the wireless driver in the Linux kernel due to lack of check of buffer length. in Snapdragon Auto,

7.8
CVE-2019-10544

Improper length check on source buffer to handle userspace data received can lead to out-of-bound access in diag handler

7.8
CVE-2019-10537

Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass th

7.8
CVE-2019-10536

Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is

9.8
CVE-2019-10525

Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB

7.8
CVE-2019-10518

Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon C

7.8
CVE-2019-10517

Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Comp

9.8
CVE-2019-10516

Multiple read overflows in MM while decoding service accept,service reject,attach reject and MT detach in Snapdragon Aut

5.5
CVE-2019-10513

Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon

9.8
CVE-2019-10500

While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Sn

9.8
CVE-2019-10487

Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Sna

5.9
CVE-2019-10482

Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p

7.8
CVE-2019-10481

Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly

7.8
CVE-2019-10480

Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmwar

7.8
CVE-2018-11980

When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o

7.1
CVE-2019-2338

Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to

7.5
CVE-2019-2337

While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which

7.8
CVE-2019-2321

Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna

9.8
CVE-2019-2320

Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd

7.8
CVE-2019-2319

HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 14,688 CVE records in our database, including 5392 critical and 7183 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 5392 critical severity (CVSS 9.0+) and 7183 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started