Qualcomm
46,786 known vulnerabilities
Top Products
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can o
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not valid
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using d
Crafted Binder Request Causes Heap UAF in MediaServer
Information disclosure possible while audio playback.
Information disclosure due to uninitialized variable.
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory.
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
A race condition exists in a driver potentially leading to a use-after-free condition.
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into t
Initial xbl_sec revision does not have all the debug policy features and critical checks.
Possible out of bound access in audio module due to lack of validation of user provided input.
Certain unprivileged processes are able to perform IOCTL calls.
Memory corruption during GNSS HAL process initialization.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU commands.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
Memory corruption while station LL statistic handling.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
Memory corruption while handling IOCTL calls in JPEG Encoder driver.
Transient DOS while processing the CU information from RNR IE.
Transient DOS while parsing BTM ML IE when per STA profile is not included.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Memory corruption while processing IOCTL calls to unmap the buffers.
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Memory corruption while processing the update SIM PB records request.
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
Memory corruption while handling the PDR in driver for getting the remote heap maps.
memory corruption when WiFi display APIs are invoked with large random inputs.
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the com
Memory corruption while maintaining memory maps of HLOS memory.
Information disclosure while sending implicit broadcast containing APP launch information.
Memory corruption while processing user packets to generate page faults.
Transient DOS while parsing probe response and assoc response frame.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the h
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption while taking snapshot when an offset variable is set by camera driver.
Frequently Asked Questions
How many CVEs affect Qualcomm?
Qualcomm has 46,786 CVE records in our database, including 9787 critical and 28782 high severity vulnerabilities. 12 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Qualcomm vulnerabilities?
Qualcomm has 9787 critical severity (CVSS 9.0+) and 28782 high severity (CVSS 7.0-8.9) vulnerabilities. 12 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Qualcomm vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Qualcomm products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Qualcomm Vulnerabilities
CyberStrike scans your infrastructure for Qualcomm vulnerabilities and provides real-time remediation guidance.
Get Started