Qualcomm Inc Snapdragon vulnerabilities

908 known vulnerabilities affecting qualcomm_inc/snapdragon.

Total CVEs
908
CISA KEV
8
actively exploited
Public exploits
0
Exploited in wild
4
Severity breakdown
CRITICAL51HIGH715MEDIUM142

Vulnerabilities

Page 42 of 46
CVE-2022-25739HIGHCVSS 7.5v9205 LTE Modemv9206 LTE Modem+22 more2023-04-13
CVE-2022-25739 [HIGH] CWE-476 CVE-2022-25739: Denial of service in modem due to missing null check while processing the ipv6 packet received durin Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
nvd
CVE-2022-25737HIGHCVSS 7.5v9205 LTE Modemv9206 LTE Modem+10 more2023-04-13
CVE-2022-25737 [HIGH] CWE-457 CVE-2022-25737: Information disclosure in modem due to missing NULL check while reading packets received from local Information disclosure in modem due to missing NULL check while reading packets received from local network
nvd
CVE-2022-33270MEDIUMCVSS 5.9vAR8035vFastConnect 6200+38 more2023-04-13
CVE-2022-33270 [MEDIUM] CWE-367 CVE-2022-33270: Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfig Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
nvd
CVE-2022-33297MEDIUMCVSS 5.5vQCA6310vQCA6320+8 more2023-04-13
CVE-2022-33297 [MEDIUM] CWE-126 CVE-2022-33297: Information disclosure due to buffer overread in Linux sensors Information disclosure due to buffer overread in Linux sensors
nvd
CVE-2022-33289MEDIUMCVSS 6.8v315 5G IoT Modemv9205 LTE Modem+222 more2023-04-13
CVE-2022-33289 [MEDIUM] CWE-129 CVE-2022-33289: Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is s Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
nvd
CVE-2022-40537CRITICALCVSS 9.8vAPQ8009vAPQ8009W+160 more2023-03-10
CVE-2022-40537 [CRITICAL] CWE-129 CVE-2022-40537: Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP re Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
nvd
CVE-2022-33256CRITICALCVSS 9.8vAR8035vQCA6390+63 more2023-03-10
CVE-2022-33256 [CRITICAL] CWE-129 CVE-2022-33256: Memory corruption due to improper validation of array index in Multi-mode call processor. Memory corruption due to improper validation of array index in Multi-mode call processor.
nvd
CVE-2022-40515CRITICALCVSS 9.8vAPQ8009vAPQ8009W+157 more2023-03-10
CVE-2022-40515 [CRITICAL] CWE-415 CVE-2022-40515: Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
nvd
CVE-2022-33250HIGHCVSS 7.5vAR8035vQCA6390+63 more2023-03-10
CVE-2022-33250 [HIGH] CWE-617 CVE-2022-33250: Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message conta Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
nvd
CVE-2022-33257HIGHCVSS 7.0vAQT1000vAR8031+138 more2023-03-10
CVE-2022-33257 [HIGH] CWE-367 CVE-2022-33257: Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
nvd
CVE-2022-25709HIGHCVSS 7.8vAR8035vQCA6174A+66 more2023-03-10
CVE-2022-25709 [HIGH] CWE-823 CVE-2022-25709: Memory corruption in modem due to use of out of range pointer offset while processing qmi msg Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
nvd
CVE-2022-33244HIGHCVSS 7.5vAR8035vQCA6391+37 more2023-03-10
CVE-2022-33244 [HIGH] CWE-617 CVE-2022-33244: Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
nvd
CVE-2022-40540HIGHCVSS 7.8vSD 8 Gen1 5GvSD888 5G+14 more2023-03-10
CVE-2022-40540 [HIGH] CWE-120 CVE-2022-40540: Memory corruption due to buffer copy without checking the size of input while loading firmware in Li Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel.
nvd
CVE-2022-33272HIGHCVSS 7.5vAR8035vQCA6390+47 more2023-03-10
CVE-2022-33272 [HIGH] CWE-617 CVE-2022-33272: Transient DOS in modem due to reachable assertion. Transient DOS in modem due to reachable assertion.
nvd
CVE-2022-40527HIGHCVSS 7.5vAR8035vCSR8811+97 more2023-03-10
CVE-2022-40527 [HIGH] CWE-617 CVE-2022-40527: Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
nvd
CVE-2022-40530HIGHCVSS 7.8vAQT1000vAR8031+187 more2023-03-10
CVE-2022-40530 [HIGH] CWE-680 CVE-2022-40530: Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization p Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
nvd
CVE-2022-25705HIGHCVSS 7.8vAPQ8009vAPQ8009W+199 more2023-03-10
CVE-2022-25705 [HIGH] CWE-680 CVE-2022-25705: Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
nvd
CVE-2022-40539HIGHCVSS 7.8vQAM8295PvQCA6574AU+23 more2023-03-10
CVE-2022-40539 [HIGH] CWE-284 CVE-2022-40539: Memory corruption in Automotive Android OS due to improper validation of array index. Memory corruption in Automotive Android OS due to improper validation of array index.
nvd
CVE-2022-40535HIGHCVSS 7.5vCSR8811vIPQ8070A+69 more2023-03-10
CVE-2022-40535 [HIGH] CWE-126 CVE-2022-40535: Transient DOS due to buffer over-read in WLAN while sending a packet to device. Transient DOS due to buffer over-read in WLAN while sending a packet to device.
nvd
CVE-2022-33242HIGHCVSS 7.8vAQT1000vAR8031+155 more2023-03-10
CVE-2022-33242 [HIGH] CWE-287 CVE-2022-33242: Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
nvd