Qualcomm
46,786 known vulnerabilities
Top Products
Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdra
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues i
Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a bu
There is potential for memory corruption in the RIL daemon due to de reference of memory outside the allocated array len
While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdr
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon
If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitt
Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used t
Exception in Modem IP stack while processing IPv6 packet in snapdragon automobile, snapdragon mobile and snapdragon wear
Improper validation of buffer length checks in the lwm2m device management protocol can leads to a buffer overflow in sn
Improper data length check while processing an event report indication can lead to a buffer overflow in snapdragon mobil
Improper length check while processing an MQTT message can lead to heap overflow in snapdragon mobile and snapdragon wea
Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdrago
Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile and snapdragon mobile in ve
Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile, snapdragon mobile and snap
Anti-rollback can be bypassed in replay scenario during app loading due to improper error handling of RPMB writes in sna
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and sna
While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdra
Improper check while accessing the local memory stack on MQTT connection request can lead to buffer overflow in snapdrag
Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside o
Spoofed SMS can be used to send a large number of messages to the device which will in turn initiate a flood of registra
Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, sn
Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile a
Improper access control on secure display buffers in snapdragon automobile, snapdragon mobile and snapdragon wear in ver
AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon m
Buffer overflow in AES-CCM and AES-GCM encryption via initialization vector in snapdragon automobile, snapdragon mobile
Possible Buffer overflow when transmitting an RTP packet in snapdragon automobile and snapdragon wear in versions MDM961
Use after free in QSH client rule processing in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile a
Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM
Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206
Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdrag
Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206,
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM965
QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and s
Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM961
When a 3rd party TEE has been loaded it is possible for the non-secure world to create a secure monitor call which will
A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wea
While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identit
Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile
Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo
Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile
Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile,
In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor
While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66
When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, S
SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile,
Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI beha
Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ f
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started