Qualcomm
46,786 known vulnerabilities
Top Products
Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdra
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snap
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto,
Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL a
Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snap
Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consu
Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Sna
Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdr
Double free issue in kernel memory mapping due to lack of memory protection mechanism in Snapdragon Compute, Snapdragon
Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet
System Services exports services without permission protect and can lead to information exposure in Snapdragon Industria
Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdrago
Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdrago
Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Sn
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s
Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from netwo
While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to
Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage da
kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdrago
A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes
Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdra
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allo
Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Com
When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attribut
kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130
NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Sn
Buffer overflow in display function due to memory copy without checking length of size using strcpy function in Snapdrag
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas
Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as t
Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon
Out of bound memory access while processing qpay due to not validating length of the response buffer provided by User. i
Out of bound memory access while processing ese transmit command due to passing Response buffer received from user in Sn
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing s
Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Number
Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to norma
When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where
Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto
Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in
Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdrago
Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in com
An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets)
Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from users
Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack
Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames.
Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snap
Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected v
Buffer over-write when this 0-byte buffer is typecasted to some other structure and hence memory corruption in Snapdrago
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started