Qualcomm Inc Snapdragon Mobile vulnerabilities
114 known vulnerabilities affecting qualcomm_inc/snapdragon_mobile.
Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL58HIGH52MEDIUM4
Vulnerabilities
Page 3 of 6
CVE-2016-10498P3CRITICALCVSS 9.8vMDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, Snapdragon_High_Med_20162018-04-18
CVE-2016-10498 [CRITICAL] CWE-74 CVE-2016-10498: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, stopping of the DTR prematurely ca
nvd
CVE-2016-10489P3CRITICALCVSS 9.8vSD 4002018-04-18
CVE-2016-10489 [CRITICAL] CWE-476 CVE-2016-10489: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, l
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, lack of address argument validation in qsee_get_tz_app_name() may lead to an untrusted pointer dereference.
nvd
CVE-2014-10057P3CRITICALCVSS 9.8vMDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 435, SD 617, SD 625, Snapdragon_High_Med_20162018-04-18
CVE-2014-10057 [CRITICAL] CWE-264 CVE-2014-10057: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 435, SD 617, SD 625, and Snapdragon_High_Med_2016, binary Calibration files under data/misc/audio have 777 permissions.
nvd
CVE-2022-22077P3HIGHCVSS 7.8vSD 8 Gen1 5G, WCD9380, WCN6855, WCN6856, WCN7850, WCN7851, WSA8830, WSA88352022-10-19
CVE-2022-22077 [HIGH] CWE-416 CVE-2022-22077: Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobil
Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile
nvd
CVE-2022-25723P3HIGHCVSS 7.8vSD 8 Gen1 5G, WCD9380, WCN6855, WCN6856, WCN7850, WCN7851, WSA8830, WSA88352022-10-19
CVE-2022-25723 [HIGH] CWE-416 CVE-2022-25723: Memory corruption in multimedia due to use after free during callback registration failure in Snapdr
Memory corruption in multimedia due to use after free during callback registration failure in Snapdragon Mobile
nvd
CVE-2015-9065P3CRITICALCVSS 9.8vMDM9615, MDM9625, MDM9635M, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 8102017-08-18
CVE-2015-9065 [CRITICAL] CWE-254 CVE-2015-9065: In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.
nvd
CVE-2014-9981P3CRITICALCVSS 9.8vMDM9625, MDM9635M, SD 400, SD 410/12, SD 615/16/SD 4152017-08-18
CVE-2014-9981 [CRITICAL] CWE-119 CVE-2014-9981: In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in
In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot.
nvd
CVE-2014-9971P3CRITICALCVSS 9.8vMDM9635M, SD 8352017-08-18
CVE-2014-9971 [CRITICAL] CWE-20 CVE-2014-9971: In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts ca
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.
nvd
CVE-2015-9133P3CRITICALCVSS 9.8vSD 400, SD 410/12, SD 617, SD 650/52, SD 800, SD 8102018-04-18
CVE-2015-9133 [CRITICAL] CWE-190 CVE-2015-9133: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 410/12, SD 617, SD 650/52, SD 800, and SD 810, if Widevine App TZ_WV_CMD_DECRYPT_VIDEO is called with a size too large, an integer overflow may occur.
nvd
CVE-2015-9221P3CRITICALCVSS 9.8vSD 400, SD 800, SD 8102018-04-18
CVE-2015-9221 [CRITICAL] CWE-476 CVE-2015-9221: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers passed by secure apps could lead to an untrusted pointer dereference.
nvd
CVE-2014-9985P3CRITICALCVSS 9.8vMDM9635M, SD 400, SD 8002018-04-18
CVE-2014-9985 [CRITICAL] CWE-388 CVE-2014-9985: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, SD 400, and SD 800, TOCTOU condition may result in bypassing error condition checks, leading to undefined behavior.
nvd
CVE-2016-10461P3CRITICALCVSS 9.8vMDM9650, SD 650/52, SD 808, SD 810, SD 820, SDX202018-04-18
CVE-2016-10461 [CRITICAL] CWE-119 CVE-2016-10461: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9650,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9650, SD 650/52, SD 808, SD 810, SD 820, and SDX20, lack of proper bounds checking may lead to a buffer overread.
nvd
CVE-2016-10454P3CRITICALCVSS 9.8vSD 425, SD 430, SD 450, SD 6252018-04-18
CVE-2016-10454 [CRITICAL] CWE-129 CVE-2016-10454: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API function, an array out-of-bounds index can occur.
nvd
CVE-2016-10495P3CRITICALCVSS 9.8vMDM9635M2018-04-18
CVE-2016-10495 [CRITICAL] CWE-118 CVE-2016-10495: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, made changes to map the scan type value to an index value that is in range.
nvd
CVE-2018-11884P3HIGHCVSS 7.8vSD 835, SD 845, SD 850, SDA6602018-10-29
CVE-2018-11884 [HIGH] CWE-119 CVE-2018-11884: Improper input validation leads to buffer overflow while processing network list offload command in
Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
nvd
CVE-2022-33217P3HIGHCVSS 7.8vSD 8 Gen1 5G, WCD9380, WCN6855, WCN6856, WCN7850, WCN7851, WSA8830, WSA88352022-10-19
CVE-2022-33217 [HIGH] CWE-120 CVE-2022-33217: Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starti
Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile
nvd
CVE-2015-9147P3CRITICALCVSS 9.8vMDM9625, MDM9635M, SD 400, SD 8002018-04-18
CVE-2015-9147 [CRITICAL] CWE-20 CVE-2015-9147: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, SD 400, and SD 800, userspace-provided pointer arguments are not validated.
nvd
CVE-2015-9151P3CRITICALCVSS 9.8vMDM9625, MDM9635M, SD 400, SD 8002018-04-18
CVE-2015-9151 [CRITICAL] CWE-20 CVE-2015-9151: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, SD 400, and SD 800, userspace-provided pointer arguments are not validated.
nvd
CVE-2018-11862P3HIGHCVSS 7.8vSD 845, SD 850, SDA6602018-10-29
CVE-2018-11862 [HIGH] CWE-119 CVE-2018-11862: Buffer overflow can happen in WLAN module due to lack of validation of the input length in Snapdrago
Buffer overflow can happen in WLAN module due to lack of validation of the input length in Snapdragon Mobile in version SD 845, SD 850, SDA660.
nvd
CVE-2018-11856P3HIGHCVSS 7.8vSD 835, SD 845, SD 8502018-10-29
CVE-2018-11856 [HIGH] CWE-119 CVE-2018-11856: Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands i
Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 835, SD 845, SD 850.
nvd