VendorsQualcommmdm9250_firmwareall versions
Vulnerabilities

Qualcomm MDM9250 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

202CVEs
CVE-2021-30254
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30255
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30319
Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2022-01-13 · Modified
7.8EPSS 0.002
CVE-2021-30268
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-01-03 · Modified
7.8EPSS 0.002
CVE-2021-30322
Possible out of bounds write due to improper validation of number of GPIOs configured in an internal parameters array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-02-11 · Modified
7.8EPSS 0.002
CVE-2021-30323
Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-02-11 · Modified
7.8EPSS 0.002
CVE-2021-1973
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30259
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30270
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-01-03 · Modified
7.8EPSS 0.002
CVE-2021-30271
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-01-03 · Modified
7.8EPSS 0.002
CVE-2021-30267
Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-01-03 · Modified
7.8EPSS 0.001
CVE-2022-33248
Integer overflow to buffer overflow in User Identity Module
Published 2023-02-09 · Modified
7.8EPSS 0.001
CVE-2022-25705
Integer Overflow to Buffer Overflow in Modem
Published 2023-03-07 · Modified
7.8EPSS 0.001
CVE-2022-22070
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-09-02 · Modified
7.8EPSS 0.001
CVE-2022-33233
Configuration weakness in modem
Published 2023-02-09 · Modified
7.8EPSS 0.001
CVE-2023-28551
Improper Restriction of Operations within the Bounds of a Memory Buffer in UTILS
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2023-28550
Improper Restriction of Operations within the Bounds of a Memory Buffer in MPP Performance
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2022-33302
Improper validation of array index in User Identity Module
Published 2023-04-04 · Modified
7.8EPSS 0.001
CVE-2023-28564
Use of Out-of-range Pointer Offset in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28565
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28541
Buffer Over-read in WLAN Host
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-28542
Buffer Over-read in WLAN HOST
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-28559
Buffer Copy Without Checking Size of Input in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2022-33266
Integer overflow to buffer overflow in Audio
Published 2023-01-06 · Modified
7.8EPSS 0.001
CVE-2022-25717
Use-After-Free Issue in Display
Published 2023-01-06 · Modified
7.8EPSS 0.001
CVE-2023-33018
Integer Overflow to Buffer Overflow in User Identity Module
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2023-33059
Buffer Copy Without Checking Size of Input in Audio
Published 2023-11-07 · Modified
7.8EPSS 0.001
CVE-2023-33120
Use After Free in Audio
Published 2024-01-02 · Modified
7.8EPSS 0.001
CVE-2024-38423
Buffer Copy Without Checking Size of Input in Graphics Linux
Published 2024-11-04 · Analyzed
7.8EPSS 0.001
CVE-2025-27053
Incorrect Calculation of Buffer Size in HLOS
Published 2025-10-09 · Analyzed
7.8EPSS 0.001
CVE-2025-47320
Out-of-bounds Write in Audio
Published 2025-12-18 · Analyzed
7.8EPSS 0.001
CVE-2026-24082
Use After Free in Automotive GPU
Published 2026-05-04 · Analyzed
7.8EPSS 0.001
CVE-2025-47386
Use After Free in Automotive Audio
Published 2026-03-02 · Analyzed
7.8EPSS 0.001
CVE-2025-47379
Use After Free in Automotive Audio
Published 2026-03-02 · Analyzed
7.8EPSS 0.001
CVE-2025-47376
Use After Free in Automotive Audio
Published 2026-03-02 · Analyzed
7.8EPSS 0.001
CVE-2025-47375
Use After Free in Automotive Audio
Published 2026-03-02 · Analyzed
7.8EPSS 0.001
CVE-2025-47404
Buffer Copy Without Checking Size of Input in Automotive Audio
Published 2026-05-04 · Analyzed
7.8EPSS 0.001
CVE-2020-11226
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-03-17 · Modified
7.5EPSS 0.009
CVE-2020-11119
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-01-21 · Modified
7.5EPSS 0.008
CVE-2020-11296
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-02-22 · Modified
7.5EPSS 0.006
← Prev4 / 6Next →