Qualcomm
46,786 known vulnerabilities
Top Products
Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received fro
Possibility of out of bound access in debug queue, if packet size field is corrupted in Snapdragon Auto, Snapdragon Comp
Improper check in video driver while processing data from video firmware can lead to integer overflow and then buffer ov
Possible OOB issue in EEPROM due to lack of check while accessing memory map array at the time of reading operation in S
Out-of-bound read in the wireless driver in the Linux kernel due to lack of check of buffer length. in Snapdragon Auto,
Improper length check on source buffer to handle userspace data received can lead to out-of-bound access in diag handler
Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass th
Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is
Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB
Use after free of a pointer in iWLAN scenario during netmgr state transition to CONNECT in Snapdragon Auto, Snapdragon C
Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Comp
Multiple read overflows in MM while decoding service accept,service reject,attach reject and MT detach in Snapdragon Aut
Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon
While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Sn
Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Sna
Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p
Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly
Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmwar
When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer o
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Sna
Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd
HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv
Out of bound read would occur while trying to read action category and action ID without validating the action length of
Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Sna
Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdrago
Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check
Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Au
Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem
Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdrag
Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdrag
Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the
Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdra
Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput
Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd
Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deall
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Au
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Au
Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application.
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non sec
SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdrag
Buffer overflow can occur while processing non-standard NAN message from user space. in Snapdragon Auto, Snapdragon Cons
Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Sn
Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values i
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started