Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 32/50
7.0
CVE-2020-3619

u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or

7.8
CVE-2020-3611

u'XBL SEC clears only ZI region when loading Qualcomm-signed segments can lead to improper access issue' in Snapdragon C

7.5
CVE-2020-11158

u'Null pointer dereference in HP OfficeJet Pro 8210 jbig2 filter due to lack of check of PDF font array leads to denial

7.8
CVE-2020-11133

u'Possible out of bound array write in rxdco cal utility due to lack of array bound check' in Snapdragon Compute, Snapdr

7.8
CVE-2020-11128

u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in

5.5
CVE-2020-11122

u'Null Pointer exception while playing crafted mkv file as data stream get deleted on secondary invalid configuration' i

7.8
CVE-2020-11120

u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the

7.5
CVE-2020-11118

u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, S

9.8
CVE-2020-11117

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arb

9.8
CVE-2020-11116

u'Possible out of bound write while processing association response received from host due to lack of check of IE length

7.5
CVE-2020-11115

u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from be

7.0
CVE-2019-14119

u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition a

7.8
CVE-2019-14117

u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from t

5.5
CVE-2019-14115

u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display sessi

7.8
CVE-2019-14089

u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-prov

7.8
CVE-2019-14074

u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn

7.8
CVE-2019-14065

u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdrago

7.8
CVE-2019-14056

u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon

9.8
CVE-2019-14052

u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing'

5.5
CVE-2019-14025

u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to

7.8
CVE-2019-13999

u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in

7.8
CVE-2019-13998

u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result

7.8
CVE-2019-13995

u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l

7.8
CVE-2019-13994

u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are

7.8
CVE-2019-13992

u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in

7.8
CVE-2019-10629

u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdra

7.8
CVE-2019-10628

u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library'

7.8
CVE-2019-10615

u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a

7.8
CVE-2019-10596

u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Sna

7.8
CVE-2019-10562

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug

7.8
CVE-2019-10527

u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SME

8.1
CVE-2018-13903

u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, S

9.8
CVE-2020-3681

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recov

7.8
CVE-2020-3701

Use after free issue while processing error notification from camx driver due to not properly releasing the sequence dat

7.5
CVE-2020-3700

Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi dri

9.8
CVE-2020-3699

Possible out of bound access while processing assoc response from host due to improper length check before copying into

9.8
CVE-2020-3698

Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response f

9.8
CVE-2020-3688

Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapd

9.8
CVE-2020-3671

Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compu

7.8
CVE-2019-14130

Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in S

7.8
CVE-2019-14124

Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Co

7.8
CVE-2019-14123

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HL

7.1
CVE-2019-14101

Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is

7.8
CVE-2019-14100

Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdrago

7.8
CVE-2019-14099

Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdra

7.8
CVE-2019-14093

Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon

7.8
CVE-2019-14037

Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Comput

7.8
CVE-2019-10580

When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been a

7.8
CVE-2020-3676

Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr

7.8
CVE-2020-3665

A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firm

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started