Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 39/50
9.8
CVE-2019-10538

Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address

8.2
CVE-2019-10510

BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote

9.8
CVE-2019-10509

Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna

7.8
CVE-2019-10508

Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon

7.8
CVE-2019-10507

Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Sna

7.8
CVE-2019-10506

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr

7.8
CVE-2019-10501

Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon

7.8
CVE-2019-10499

Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-

7.8
CVE-2019-10498

Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Co

7.8
CVE-2019-10497

Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos

7.8
CVE-2019-10492

Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W,

7.5
CVE-2019-10489

Possible null-pointer dereference can occur while parsing avi clip during copy in Snapdragon Auto, Snapdragon Compute, S

7.8
CVE-2019-2346

Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation.

7.0
CVE-2019-2345

Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume

5.5
CVE-2019-2343

Out of bound read and information disclosure in firmware due to insufficient checking of an embedded structure that can

7.5
CVE-2019-2334

Null pointer dereferencing can happen when playing the clip with wrong block group id in Snapdragon Auto, Snapdragon Com

5.5
CVE-2019-2330

improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapd

7.8
CVE-2019-2328

Possible buffer overflow when number of channels passed is more than size of channel mapping array in Snapdragon Auto, S

9.8
CVE-2019-2327

Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute,

7.8
CVE-2019-2326

Data token is received from ADSP and is used without validation as an index into the array leads to out of bound access

9.8
CVE-2019-2322

Buffer overflow can occur when playing specific clip which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapd

8.8
CVE-2019-2316

When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT,

7.0
CVE-2019-2314

Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Sn

7.8
CVE-2019-2312

When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer

9.8
CVE-2019-2309

While storing calibrated data from firmware in cache, An integer overflow may occur since data length received may excee

7.8
CVE-2019-2308

User application could potentially make RPC call to the fastrpc driver and the driver will allow the message to go throu

9.8
CVE-2019-2307

Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configura

7.8
CVE-2019-2306

Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdr

9.8
CVE-2019-2305

Out of bound access when reason code is extracted from frame data without validating the frame length in Snapdragon Auto

7.8
CVE-2019-2301

Possibility of out-of-bound read if id received from SPI is not in range of FIFO in Snapdragon Auto, Snapdragon Compute,

7.8
CVE-2019-2299

An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon

7.8
CVE-2019-2298

Protection is missing while accessing md sessions info via macro which can lead to use-after-free in Snapdragon Auto, Sn

7.8
CVE-2019-2293

Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer

7.8
CVE-2019-2290

Multiple open and close from multiple threads will lead camera driver to access destroyed session data pointer in Snapdr

7.8
CVE-2019-2281

An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapd

7.8
CVE-2019-2278

User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto,

9.8
CVE-2019-2276

Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from

7.5
CVE-2019-2273

IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute,

7.8
CVE-2019-2272

Buffer overflow can occur in display function due to lack of validation of header block size set by user. in Snapdragon

7.8
CVE-2019-2263

Access to freed memory can happen while reading from diag driver due to use after free issue in Snapdragon Auto, Snapdra

9.8
CVE-2019-2254

Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput

9.8
CVE-2019-2253

Buffer over-read can occur while parsing an ogg file with a corrupted comment block. in Snapdragon Auto, Snapdragon Conn

5.5
CVE-2019-2241

While rendering the layout background, Error status check is not caught properly and also incorrect status handling is b

5.5
CVE-2019-2240

While sending the rendered surface content to the screen, Error handling is not properly checked results in an unpredict

5.5
CVE-2019-2239

Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto

7.8
CVE-2019-2238

Lack of check of data type can lead to subsequent loop-expression potentially go negative and the condition will still e

5.5
CVE-2019-2237

Failure in taking appropriate action to handle the error case If keypad gpio deactivation fails leads to silent failure

5.5
CVE-2019-2236

Null pointer dereference during secure application termination using specific application ids. in Snapdragon Auto, Snapd

7.8
CVE-2019-2235

Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in

7.5
CVE-2018-13897

Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Sna

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started