Qualcomm Inc Snapdragon Mobile vulnerabilities
114 known vulnerabilities affecting qualcomm_inc/snapdragon_mobile.
Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL58HIGH52MEDIUM4
Vulnerabilities
Page 4 of 6
CVE-2017-18128P3HIGHCVSS 7.5vSD 845, SD 8502018-04-11
CVE-2017-18128 [HIGH] CVE-2017-18128: In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, impr
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, improper access control while configuring MPU protecting error correction registers may potentially lead to exposure of related secured data.
nvd
CVE-2015-9146P3CRITICALCVSS 9.8vMDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, SDX202018-04-18
CVE-2015-9146 [CRITICAL] CWE-20 CVE-2015-9146: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, SD 400, SD 800, SD 835, SD 845, SD 850, and SDX20, when QDI read, write, or ioctl are called, the passed-in pointer is not properly validated before accessing it for the delayed response.
nvd
CVE-2014-10039P3CRITICALCVSS 9.8vMDM9625, SD 400, SD 8002018-04-18
CVE-2014-10039 [CRITICAL] CWE-19 CVE-2014-10039: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, SD 400, and SD 800, calling qsee_app_entry_return() without first calling qsee_app_entry() will cause the stack to be restored to an older state resulting in a return to an unexpected location.
nvd
CVE-2018-11876P3HIGHCVSS 7.8vSD 835, SD 845, SD 850, SDA6602018-10-29
CVE-2018-11876 [HIGH] CWE-119 CVE-2018-11876: Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdrago
Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.
nvd
CVE-2018-11872P3HIGHCVSS 7.8vSD 845, SD 850, SDA6602018-10-29
CVE-2018-11872 [HIGH] CWE-20 CVE-2018-11872: Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands i
Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660
nvd
CVE-2018-11257P3HIGHCVSS 7.8vSD 210/SD 212/SD 205, SD 845, SD 8502018-07-06
CVE-2018-11257 [HIGH] CVE-2018-11257: Permissions, Privileges, and Access Controls in TA in Snapdragon Mobile has an options that allows R
Permissions, Privileges, and Access Controls in TA in Snapdragon Mobile has an options that allows RPMB erase for secure devices in versions SD 210/SD 212/SD 205, SD 845, SD 850.
nvd
CVE-2015-9173P3CRITICALCVSS 9.8vSD 410/12, SD 617, SD 650/52, SD 800, SD 808, SD 8102018-04-18
CVE-2015-9173 [CRITICAL] CWE-119 CVE-2015-9173: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12, SD 617, SD 650/52, SD 800, SD 808, and SD 810, missing of return value check in memscpy can cause memory corruption in TQS App.
nvd
CVE-2015-9131P3HIGHCVSS 7.5vSD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 8102018-04-18
CVE-2015-9131 [HIGH] CWE-20 CVE-2015-9131: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, and SD 810, lack of input validation in qsee can lead to unauthorized memory access.
nvd
CVE-2015-9194P3HIGHCVSS 7.5vSD 210/SD 212/SD 205,SD 400,SD 425,SD 427,SD 430,SD 435,SD 450,SD 617,SD 625,SD 650/52,SD 800,SD 845,Snapdragon_High_Med_20162018-04-18
CVE-2015-9194 [HIGH] CWE-200 CVE-2015-9194: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 845, and Snapdragon_High_Med_2016, during module load at TZ Startup, memory statically allocated by modules was not being properly set to zero first. Allowi
nvd
CVE-2014-10055P3HIGHCVSS 7.5vSD 400, SD 8002018-04-18
CVE-2014-10055 [HIGH] CWE-200 CVE-2014-10055: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 an
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected contents if HLOS doesn't request for security restoration for OCMEM xPU's.
nvd
CVE-2016-10385P3CRITICALCVSS 9.8vSD 210/SD 212/SD 205, SD 430, SD 615/16/SD 415, SD 625, SD 8202017-08-18
CVE-2016-10385 [CRITICAL] CWE-416 CVE-2016-10385: In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vul
In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in IMS RCS.
nvd
CVE-2016-10496P4CRITICALCVSS 9.8vMDM9635M, SD 210/SD 212/SD 205, SD 410/12, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 8102018-04-18
CVE-2016-10496 [CRITICAL] CWE-476 CVE-2016-10496: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, SD 210/SD 212/SD 205, SD 410/12, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, and SD 810, A NULL pointer dereference can occur during an SSL handshake.
nvd
CVE-2018-11861P3HIGHCVSS 7.8vSD 845, SD 850, SDA6602018-10-29
CVE-2018-11861 [HIGH] CWE-119 CVE-2018-11861: Buffer overflow can happen in WLAN function due to lack of validation of the input length in Snapdra
Buffer overflow can happen in WLAN function due to lack of validation of the input length in Snapdragon Mobile in version SD 845, SD 850, SDA660.
nvd
CVE-2018-11854P3HIGHCVSS 7.8vSD 835, SD 845, SD 850, SDA6602018-10-26
CVE-2018-11854 [HIGH] CWE-119 CVE-2018-11854: Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mo
Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
nvd
CVE-2020-3701P3HIGHCVSS 7.8vSaipan, SM8250, SXR21302020-07-30
CVE-2020-3701 [HIGH] CWE-416 CVE-2020-3701: Use after free issue while processing error notification from camx driver due to not properly releas
Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon Mobile in Saipan, SM8250, SXR2130
nvd
CVE-2018-11858P3HIGHCVSS 7.8vSD 835, SD 845, SD 8502018-10-29
CVE-2018-11858 [HIGH] CWE-119 CVE-2018-11858: When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE
When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.
nvd
CVE-2017-18143P3HIGHCVSS 7.5vSD 845, SD 8502018-04-11
CVE-2017-18143 [HIGH] CVE-2017-18143: In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, on a
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, on a secure device, PD dumps are collected when debugging is not enabled.
nvd
CVE-2015-9124P4CRITICALCVSS 9.1vMDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, SD 8102018-04-18
CVE-2015-9124 [CRITICAL] CWE-476 CVE-2015-9124: In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9640, MDM9645, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, SD 808, and SD 810, the device may crash while accessing an invalid pointer or expose otherwise inaccessible memory contents.
nvd
CVE-2017-18297P4HIGHCVSS 7.8vSD 425, SD 430, SD 450, SD 625, SD 650/52, SD 8202018-10-23
CVE-2017-18297 [HIGH] CWE-415 CVE-2017-18297: Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 42
Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820.
nvd
CVE-2018-11867P4HIGHCVSS 7.8vSD 8452018-10-29
CVE-2018-11867 [HIGH] CWE-119 CVE-2018-11867: Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to
Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.
nvd