Qualcomm
46,786 known vulnerabilities
Top Products
Out of bound write can occur in radio measurement request if STA receives multiple invalid rrm measurement request from
Possible buffer overflow while playing mkv clip due to lack of validation of atom size buffer in Snapdragon Auto, Snapdr
Memory failure in SKB if it fails to to add the requested padding to the skb in low memory targets or targets with major
Privilege escalation by using an altered debug policy image can occur as the XPU protecting the debug policy regions are
Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snap
Buffer overflow can occur in In WLAN firmware while unwraping data using CCMP cipher suite during parsing of EAPOL hands
Potential buffer overflow while processing CBF frames due to lack of check of buffer length before copy in Snapdragon Au
Possible buffer overflow while handling NAN reception of NMF in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
Buffer overflow can occur in function wlan firmware while copying association frame content if frame length is more than
Kernel was reading the CSL defined reserved field as uint16 instead of uint32 which could lead to memory overflow in Sna
Slab-out-of-bounds access can occur if the context pointer is invalid due to lack of null check on pointer before access
Null pointer dereference issue in radio interface layer due to lack of null check in sapmodule destructor in Snapdragon
Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls
Multiple Read overflows issue due to improper length check while decoding tau reject/tau accept/detach request/attach re
Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, S
Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filen
Multiple Read overflows issue due to improper length check while decoding dedicated_eps_bearer_req/ act_def_context_req/
Multiple Read overflows issue due to improper length check while decoding RAU accept/PDN disconnect Rej/Modify EPS ctxt
Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute,
Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking w
Multiple Read overflows issue due to improper length check while decoding 3G attach accept/ SMS/ pdn connection reject/
Out of bound memory access while processing TZ command handler due to improper input validation on response length recei
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p
Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapd
Out of bound access in diag services when DCI command buffer reallocation is not done properly with required capacity in
While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int dat
Possible integer overflow can happen in host driver while processing user controlled string due to improper validation o
Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from u
Use after free issue when MAP and UNMAP calls at same time as data structure used my MAP may be freed by UNMAP function
Kernel memory error in debug module due to improper check of user data length before copying into memory in Snapdragon A
Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media l
Out of bound write can happen due to lack of check of array index value while calculating it. in Snapdragon Auto, Snapdr
Information disclosure issue occurs as there is no binding between the secure keypad session and the secure display sess
Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdr
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s
Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon C
Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon
Missing length check before copying the data from kernel space to userspace through the copy function can lead to buffer
String error while processing non standard SIP messages received can lead to buffer overread and then denial of service
When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snap
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Com
Side channel issue in QTEE due to usage of non-time-constant comparison function such as memcmp or strcmp in Snapdragon
An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An
An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A devic
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileg
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) s
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (MSM8939, MSM8996, MSM8998, Exynos7580, Exynos8
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7
An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflo
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started