Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 31/50
7.8
CVE-2020-3684

u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader

7.8
CVE-2020-3678

u'A buffer overflow could occur if the API is improperly used due to UIE init does not contain a buffer size a param' in

9.8
CVE-2020-3673

u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check

9.1
CVE-2020-3670

u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Informati

9.8
CVE-2020-3657

u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from

9.8
CVE-2020-3654

u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying int

7.8
CVE-2020-3638

u'An Unaligned address or size can propagate to the database due to improper page permissions and can lead to improper a

7.8
CVE-2020-11174

u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdra

7.0
CVE-2020-11173

u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, S

9.8
CVE-2020-11172

u'fscanf reads a string from a file and stores its contents on a statically allocated stack memory which leads to stack

9.1
CVE-2020-11169

u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Sna

7.8
CVE-2020-11164

u'Third-party app may also call the broadcasts in Perfdump and cause privilege escalation issue due to improper access c

7.8
CVE-2020-11162

u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI devic

7.5
CVE-2020-11157

u'Lack of handling unexpected control messages while encryption was in progress can terminate the connection and thus le

8.1
CVE-2020-11156

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer

8.8
CVE-2020-11155

u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.

8.8
CVE-2020-11154

u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before cop

9.8
CVE-2020-11153

u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to re

8.1
CVE-2020-11141

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap configuration request rece

7.8
CVE-2020-11125

u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devic

8.8
CVE-2020-11114

u'Bluetooth devices does not properly restrict the L2CAP payload length allowing users in radio range to cause a buffer

6.7
CVE-2020-25859

The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() ca

7.5
CVE-2020-25858

The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not val

5.4
CVE-2019-18991

A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d

5.5
CVE-2020-3679

u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known

5.5
CVE-2020-3674

Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdr

7.8
CVE-2020-3656

Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI

9.1
CVE-2020-3634

u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdrago

7.1
CVE-2020-3617

u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing

7.5
CVE-2020-11135

u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer

7.8
CVE-2020-11129

u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail

7.8
CVE-2020-11124

u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max clien

6.5
CVE-2020-3702

u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi

9.8
CVE-2020-3675

u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute'

9.8
CVE-2020-3669

u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Sna

9.8
CVE-2020-3668

u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while par

9.8
CVE-2020-3667

u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in

7.8
CVE-2020-3666

u'Out of bounds memory access during memory copy while processing Host command' in Snapdragon Auto, Snapdragon Compute,

7.8
CVE-2020-3648

u'Possible out of bound write in DSP driver code due to lack of check of data received from user' in Snapdragon Auto, Sn

7.8
CVE-2020-3647

u'Potential buffer overflow when accessing npu debugfs node "off"/"log" with large buffer size' in Snapdragon Compute, S

7.8
CVE-2020-3646

u'Buffer overflow seen as the destination buffer size is lesser than the source buffer size in video application' in Sna

5.5
CVE-2020-3644

u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display s

5.5
CVE-2020-3643

u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snap

7.8
CVE-2020-3640

u'Resizing the usage table header before passing all the checks leads to the function exiting with a usage table in inva

7.8
CVE-2020-3636

u'Out of bound writes happen when accessing usage_table header entry beyond the memory allocated for the header' in Snap

7.8
CVE-2020-3629

u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining

7.8
CVE-2020-3624

u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage i

7.8
CVE-2020-3622

u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not va

5.5
CVE-2020-3621

u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIF

5.5
CVE-2020-3620

u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM tr

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started