Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Qualcomm

46,786 known vulnerabilities

529
CRITICAL
1,510
HIGH
426
MEDIUM

Top Products

ar8035 643 ar8035 firmware 621 aqt1000 616 mdm9206 611 mdm9206 firmware 603 aqt1000 firmware 586 mdm9607 564 mdm9607 firmware 562 mdm9650 483 mdm9650 firmware 473
2,465 CVEs · Page 9/50
6.7
CVE-2024-33040

Memory corruption while invoking redundant release command to release one buffer from user space as race condition can o

6.7
CVE-2024-33039

Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not valid

6.1
CVE-2024-33037

Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC

6.7
CVE-2024-33036

Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in

8.4
CVE-2018-5852

An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using d

7.8
CVE-2018-11816

Crafted Binder Request Causes Heap UAF in MediaServer

8.4
CVE-2017-18307

Information disclosure possible while audio playback.

8.4
CVE-2017-18306

Information disclosure due to uninitialized variable.

8.4
CVE-2016-10408

QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory.

8.4
CVE-2018-11952

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

9.8
CVE-2018-11922

Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.

8.4
CVE-2017-18153

A race condition exists in a driver potentially leading to a use-after-free condition.

9.8
CVE-2017-17772

In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

8.4
CVE-2017-15832

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

9.8
CVE-2017-11076

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into t

8.4
CVE-2016-10394

Initial xbl_sec revision does not have all the debug policy features and critical checks.

6.7
CVE-2021-30299

Possible out of bound access in audio module due to lack of validation of user provided input.

6.7
CVE-2017-9711

Certain unprivileged processes are able to perform IOCTL calls.

7.8
CVE-2024-38424

Memory corruption during GNSS HAL process initialization.

7.8
CVE-2024-38423

Memory corruption while processing GPU page table switch.

7.8
CVE-2024-38422

Memory corruption while processing voice packet with arbitrary data received from ADSP.

7.8
CVE-2024-38421

Memory corruption while processing GPU commands.

7.8
CVE-2024-38419

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

7.8
CVE-2024-38415

Memory corruption while handling session errors from firmware.

7.8
CVE-2024-38410

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

7.8
CVE-2024-38409

Memory corruption while station LL statistic handling.

8.2
CVE-2024-38408

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

7.8
CVE-2024-38407

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

7.8
CVE-2024-38406

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

7.5
CVE-2024-38405

Transient DOS while processing the CU information from RNR IE.

7.5
CVE-2024-38403

Transient DOS while parsing BTM ML IE when per STA profile is not included.

7.5
CVE-2024-33068

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

6.7
CVE-2024-33033

Memory corruption while processing IOCTL calls to unmap the buffers.

6.7
CVE-2024-33032

Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

6.7
CVE-2024-33031

Memory corruption while processing the update SIM PB records request.

6.7
CVE-2024-33030

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

6.7
CVE-2024-33029

Memory corruption while handling the PDR in driver for getting the remote heap maps.

6.7
CVE-2024-23386

memory corruption when WiFi display APIs are invoked with large random inputs.

7.5
CVE-2024-23385

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

6.7
CVE-2024-23377

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the com

7.8
CVE-2024-43047 KEV

Memory corruption while maintaining memory maps of HLOS memory.

6.1
CVE-2024-38425

Information disclosure while sending implicit broadcast containing APP launch information.

8.4
CVE-2024-38399

Memory corruption while processing user packets to generate page faults.

7.5
CVE-2024-38397

Transient DOS while parsing probe response and assoc response frame.

8.2
CVE-2024-33073

Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

7.5
CVE-2024-33071

Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

7.5
CVE-2024-33070

Transient DOS while parsing ESP IE from beacon/probe response frame.

7.5
CVE-2024-33069

Transient DOS when transmission of management frame sent by host is not successful and error status is received in the h

9.8
CVE-2024-33066

Memory corruption while redirecting log file to any file location with any file name.

8.4
CVE-2024-33065

Memory corruption while taking snapshot when an offset variable is set by camera driver.

Frequently Asked Questions

How many CVEs affect Qualcomm?

Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Qualcomm vulnerabilities?

Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Qualcomm vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Qualcomm Vulnerabilities

CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.

Get Started