Qualcomm Inc Snapdragon vulnerabilities

908 known vulnerabilities affecting qualcomm_inc/snapdragon.

Total CVEs
908
CISA KEV
8
actively exploited
Public exploits
0
Exploited in wild
4
Severity breakdown
CRITICAL51HIGH715MEDIUM142

Vulnerabilities

Page 21 of 46
CVE-2024-38425MEDIUMCVSS 6.1vFastConnect 6900vFastConnect 7800+22 more2024-10-07
CVE-2024-38425 [MEDIUM] CWE-285 CVE-2024-38425: Information disclosure while sending implicit broadcast containing APP launch information. Information disclosure while sending implicit broadcast containing APP launch information.
nvd
CVE-2024-23370MEDIUMCVSS 6.7vQCA6584AUvQCA6698AQ+9 more2024-10-07
CVE-2024-23370 [MEDIUM] CWE-416 CVE-2024-23370: Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
nvd
CVE-2024-23375MEDIUMCVSS 6.7vSA4150PvSA4155P+12 more2024-10-07
CVE-2024-23375 [MEDIUM] CWE-120 CVE-2024-23375: Memory corruption during the network scan request. Memory corruption during the network scan request.
nvd
CVE-2024-23378MEDIUMCVSS 6.7vQAM8255PvQAM8650P+16 more2024-10-07
CVE-2024-23378 [MEDIUM] CWE-120 CVE-2024-23378: Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playbac Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
nvd
CVE-2024-23374MEDIUMCVSS 6.7vFastConnect 6900vFastConnect 7800+24 more2024-10-07
CVE-2024-23374 [MEDIUM] CWE-121 CVE-2024-23374: Memory corruption is possible when an attempt is made from userspace or console to write some haptic Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.
nvd
CVE-2024-33051HIGHCVSS 7.5v315 5G IoT Modemv9206 LTE Modem+289 more2024-09-02
CVE-2024-33051 [HIGH] CWE-126 CVE-2024-33051: Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
nvd
CVE-2024-23362HIGHCVSS 7.1v9205 LTE ModemvAQT1000+225 more2024-09-02
CVE-2024-23362 [HIGH] CWE-20 CVE-2024-23362: Cryptographic issue while parsing RSA keys in COBR format. Cryptographic issue while parsing RSA keys in COBR format.
nvd
CVE-2024-23365HIGHCVSS 8.4vFastConnect 7800vQAM8255P+46 more2024-09-02
CVE-2024-23365 [HIGH] CWE-416 CVE-2024-23365: Memory corruption while releasing shared resources in MinkSocket listener thread. Memory corruption while releasing shared resources in MinkSocket listener thread.
nvd
CVE-2024-33035HIGHCVSS 8.4vFastConnect 6200vFastConnect 6700+88 more2024-09-02
CVE-2024-33035 [HIGH] CWE-190 CVE-2024-33035: Memory corruption while calculating total metadata size when a very high reserved size is requested Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
nvd
CVE-2024-33047HIGHCVSS 7.8vFastConnect 6700vFastConnect 6900+22 more2024-09-02
CVE-2024-33047 [HIGH] CWE-126 CVE-2024-33047: Memory corruption when the captureRead QDCM command is invoked from user-space. Memory corruption when the captureRead QDCM command is invoked from user-space.
nvd
CVE-2024-38402HIGHCVSS 7.8vAR8035vCSRA6620+166 more2024-09-02
CVE-2024-38402 [HIGH] CWE-416 CVE-2024-38402: Memory corruption while processing IOCTL call for getting group info. Memory corruption while processing IOCTL call for getting group info.
nvd
CVE-2024-23358HIGHCVSS 7.5vAPQ8017vAPQ8037+51 more2024-09-02
CVE-2024-23358 [HIGH] CWE-126 CVE-2024-23358: Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
nvd
CVE-2024-33042HIGHCVSS 7.8vAPQ8017vAQT1000+200 more2024-09-02
CVE-2024-33042 [HIGH] CWE-120 CVE-2024-33042: Memory corruption when Alternative Frequency offset value is set to 255. Memory corruption when Alternative Frequency offset value is set to 255.
nvd
CVE-2024-23364HIGHCVSS 7.5vAR8035vFastConnect 6200+176 more2024-09-02
CVE-2024-23364 [HIGH] CWE-126 CVE-2024-23364: Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSS Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
nvd
CVE-2024-33057HIGHCVSS 7.5vAR8035vCSR8811+169 more2024-09-02
CVE-2024-33057 [HIGH] CWE-126 CVE-2024-33057: Transient DOS while parsing the multi-link element Control field when common information length chec Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
nvd
CVE-2024-38401HIGHCVSS 7.8vAR8035vC-V2X 9150+38 more2024-09-02
CVE-2024-38401 [HIGH] CWE-416 CVE-2024-38401: Memory corruption while processing concurrent IOCTL calls. Memory corruption while processing concurrent IOCTL calls.
nvd
CVE-2024-33038HIGHCVSS 7.8vFastConnect 6700vFastConnect 6900+43 more2024-09-02
CVE-2024-33038 [HIGH] CWE-822 CVE-2024-33038: Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
nvd
CVE-2024-33048HIGHCVSS 7.5vAR8035vCSR8811+187 more2024-09-02
CVE-2024-33048 [HIGH] CWE-126 CVE-2024-33048: Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
nvd
CVE-2024-33054HIGHCVSS 7.8vFastConnect 6700vFastConnect 6900+31 more2024-09-02
CVE-2024-33054 [HIGH] CWE-120 CVE-2024-33054: Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machi Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
nvd
CVE-2024-33060HIGHCVSS 7.8v315 5G IoT ModemvAQT1000+247 more2024-09-02
CVE-2024-33060 [HIGH] CWE-416 CVE-2024-33060: Memory corruption when two threads try to map and unmap a single node simultaneously. Memory corruption when two threads try to map and unmap a single node simultaneously.
nvd