Qualcomm
46,786 known vulnerabilities
Top Products
Out of bound access can occur due to buffer copy without checking size of input received from WLAN firmware in Snapdrago
Improper validation for inputs received from firmware can lead to an out of bound write issue in video driver. in Snapdr
Shared memory gets updated with invalid data and may lead to access beyond the allocated memory. in Snapdragon Auto, Sna
Out of bound read can happen due to lack of NULL termination on user controlled data in WLAN in Snapdragon Auto, Snapdra
Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validati
Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer
Unauthorized access from GPU subsystem to HLOS or other non secure subsystem memory can lead to information disclosure i
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Sna
Possible buffer overflow at the end of iterating loop while getting the version info and lead to information disclosure.
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel
Lack of check to prevent the buffer length taking negative values can lead to stack overflow. in Snapdragon Auto, Snapdr
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto,
Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity,
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr
A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,
Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons
Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in
Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon C
A buffer overflow can occur while processing an extscan hotlist event in Snapdragon Auto, Snapdragon Consumer Electronic
Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing com
Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon
Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectiv
Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulti
Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon
While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if
The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge
Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decodi
Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in
Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum
Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame
The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdr
Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT
Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto,
Lack of input validation in WLAN function can lead to potential heap overflow in Snapdragon Auto, Snapdragon Consumer IO
Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT
Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdrag
Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapd
Buffer overflow can occur if invalid header tries to overwrite the existing buffer which fix size allocation in Snapdrag
Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing
Possible integer underflow can happen when calculating length of elementary stream map from invalid packet length which
Possible integer underflow can happen when calculating length of elementary stream info from invalid section length whic
Error in parsing PMT table frees the memory allocated for the map section but does not reset the context map section ref
Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdrag
Processing messages after error may result in user after free memory fault in Snapdragon Auto, Snapdragon Compute, Snapd
Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an
Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snap
Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compu
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started