Qualcomm Inc Snapdragon vulnerabilities
908 known vulnerabilities affecting qualcomm_inc/snapdragon.
Total CVEs
908
CISA KEV
8
actively exploited
Public exploits
0
Exploited in wild
4
Severity breakdown
CRITICAL51HIGH715MEDIUM142
Vulnerabilities
Page 37 of 46
CVE-2023-28576HIGHCVSS 7.0vFastConnect 6800vFastConnect 6900+29 more2023-08-08
CVE-2023-28576 [HIGH] CWE-367 CVE-2023-28576: The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in users
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
nvd
CVE-2023-21652HIGHCVSS 7.1vAQT1000vAR8035+118 more2023-08-08
CVE-2023-21652 [HIGH] CWE-320 CVE-2023-21652: Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
nvd
CVE-2023-21651HIGHCVSS 7.8vAQT1000vAR8031+138 more2023-08-08
CVE-2023-21651 [HIGH] CWE-704 CVE-2023-21651: Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
nvd
CVE-2023-28537HIGHCVSS 7.8v315 5G IoT ModemvAPQ8017+175 more2023-08-08
CVE-2023-28537 [HIGH] CWE-190 CVE-2023-28537: Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory corruption while allocating memory in COmxApeDec module in Audio.
nvd
CVE-2023-28555HIGHCVSS 7.5vAR8035vFastConnect 6200+68 more2023-08-08
CVE-2023-28555 [HIGH] CWE-126 CVE-2023-28555: Transient DOS in Audio while remapping channel buffer in media codec decoding.
Transient DOS in Audio while remapping channel buffer in media codec decoding.
nvd
CVE-2023-21627HIGHCVSS 7.8vAQT1000vQCA6390+46 more2023-08-08
CVE-2023-21627 [HIGH] CWE-20 CVE-2023-21627: Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
nvd
CVE-2023-21626HIGHCVSS 7.1vAPQ8009vAPQ8017+183 more2023-08-08
CVE-2023-21626 [HIGH] CWE-320 CVE-2023-21626: Cryptographic issue in HLOS due to improper authentication while performing key velocity checks usin
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
nvd
CVE-2023-28575HIGHCVSS 7.8vAQT1000vC-V2X 9150+58 more2023-08-08
CVE-2023-28575 [HIGH] CWE-823 CVE-2023-28575: The cam_get_device_priv function does not check the type of handle being returned (device/session/li
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
nvd
CVE-2023-21647MEDIUMCVSS 6.5vQCA6390vQCA6391+41 more2023-08-08
CVE-2023-21647 [MEDIUM] CWE-20 CVE-2023-21647: Information disclosure in Bluetooth when an GATT packet is received due to improper input validation
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
nvd
CVE-2023-21631CRITICALCVSS 9.8v315 5G IoT Modemv9205 LTE Modem+154 more2023-07-04
CVE-2023-21631 [CRITICAL] CWE-20 CVE-2023-21631: Weak Configuration due to improper input validation in Modem while processing LTE security mode comm
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
nvd
CVE-2023-21640HIGHCVSS 7.8vFastConnect 6900vFastConnect 7800+4 more2023-07-04
CVE-2023-21640 [HIGH] CWE-120 CVE-2023-21640: Memory corruption in Linux when the file upload API is called with parameters having large buffer.
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
nvd
CVE-2023-22386HIGHCVSS 7.8vAR8035vCSR8811+199 more2023-07-04
CVE-2023-22386 [HIGH] CWE-120 CVE-2023-22386: Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.
nvd
CVE-2023-21639HIGHCVSS 7.8vAQT1000vFastConnect 6200+20 more2023-07-04
CVE-2023-21639 [HIGH] CWE-120 CVE-2023-21639: Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL cl
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
nvd
CVE-2023-21635HIGHCVSS 7.8vAQT1000vCSRB31024+47 more2023-07-04
CVE-2023-21635 [HIGH] CWE-120 CVE-2023-21635: Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
nvd
CVE-2023-21641HIGHCVSS 7.8vFastConnect 6900vFastConnect 7800+13 more2023-07-04
CVE-2023-21641 [HIGH] CWE-264 CVE-2023-21641: An app with non-privileged access can change global system brightness and cause undesired system beh
An app with non-privileged access can change global system brightness and cause undesired system behavior.
nvd
CVE-2023-22387HIGHCVSS 7.8v315 5G IoT ModemvAPQ8017+269 more2023-07-04
CVE-2023-22387 [HIGH] CWE-823 CVE-2023-22387: Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
nvd
CVE-2023-21637HIGHCVSS 7.8vAQT1000vFastConnect 6200+53 more2023-07-04
CVE-2023-21637 [HIGH] CWE-119 CVE-2023-21637: Memory corruption in Linux while calling system configuration APIs.
Memory corruption in Linux while calling system configuration APIs.
nvd
CVE-2023-24851HIGHCVSS 7.8vAR8035vCSR8811+189 more2023-07-04
CVE-2023-24851 [HIGH] CWE-120 CVE-2023-24851: Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
Memory Corruption in WLAN HOST while parsing QMI response message from firmware.
nvd
CVE-2023-24854HIGHCVSS 7.8vAR8035vCSRA6620+161 more2023-07-04
CVE-2023-24854 [HIGH] CWE-121 CVE-2023-24854: Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.
nvd
CVE-2023-21672HIGHCVSS 7.8vFastConnect 6700vFastConnect 6900+55 more2023-07-04
CVE-2023-21672 [HIGH] CWE-416 CVE-2023-21672: Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunne
Memory corruption in Audio while running concurrent tunnel playback or during concurrent audio tunnel recording sessions.
nvd