Qualcomm
46,786 known vulnerabilities
Top Products
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address
BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote
Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna
Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon
Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Sna
While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr
Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon
Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-
Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Co
Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos
Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W,
Possible null-pointer dereference can occur while parsing avi clip during copy in Snapdragon Auto, Snapdragon Compute, S
Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation.
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume
Out of bound read and information disclosure in firmware due to insufficient checking of an embedded structure that can
Null pointer dereferencing can happen when playing the clip with wrong block group id in Snapdragon Auto, Snapdragon Com
improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapd
Possible buffer overflow when number of channels passed is more than size of channel mapping array in Snapdragon Auto, S
Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute,
Data token is received from ADSP and is used without validation as an index into the array leads to out of bound access
Buffer overflow can occur when playing specific clip which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapd
When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT,
Possible race condition that will cause a use-after-free when writing to two sysfs entries at nearly the same time in Sn
When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer
While storing calibrated data from firmware in cache, An integer overflow may occur since data length received may excee
User application could potentially make RPC call to the fastrpc driver and the driver will allow the message to go throu
Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configura
Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdr
Out of bound access when reason code is extracted from frame data without validating the frame length in Snapdragon Auto
Possibility of out-of-bound read if id received from SPI is not in range of FIFO in Snapdragon Auto, Snapdragon Compute,
An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon
Protection is missing while accessing md sessions info via macro which can lead to use-after-free in Snapdragon Auto, Sn
Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer
Multiple open and close from multiple threads will lead camera driver to access destroyed session data pointer in Snapdr
An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapd
User keystore signature is ignored in boot and can lead to bypass boot image signature verification in Snapdragon Auto,
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from
IOMMU page fault while playing h265 video file leads to denial of service issue in Snapdragon Auto, Snapdragon Compute,
Buffer overflow can occur in display function due to lack of validation of header block size set by user. in Snapdragon
Access to freed memory can happen while reading from diag driver due to use after free issue in Snapdragon Auto, Snapdra
Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput
Buffer over-read can occur while parsing an ogg file with a corrupted comment block. in Snapdragon Auto, Snapdragon Conn
While rendering the layout background, Error status check is not caught properly and also incorrect status handling is b
While sending the rendered surface content to the screen, Error handling is not properly checked results in an unpredict
Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto
Lack of check of data type can lead to subsequent loop-expression potentially go negative and the condition will still e
Failure in taking appropriate action to handle the error case If keypad gpio deactivation fails leads to silent failure
Null pointer dereference during secure application termination using specific application ids. in Snapdragon Auto, Snapd
Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Sna
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started