VendorsQualcommqcm6490_firmwareall versions
Vulnerabilities

Qualcomm QCM6490 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

599CVEs
CVE-2021-35097
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-09-02 · Modified
7.3EPSS 0.002
CVE-2025-59617
Use After Free in Computer Vision
Published 2026-07-06 · Analyzed
7.3EPSS 0.001
CVE-2025-47383
Missing Cryptographic Step in Data Modem
Published 2026-03-02 · Analyzed
7.2EPSS 0.001
CVE-2026-24089
Improper Validation of Syntactic Correctness of Input in Kernel
Published 2026-06-01 · Analyzed
7.2EPSS 0.001
CVE-2026-24091
Improper Validation of Syntactic Correctness of Input in Display
Published 2026-06-01 · Analyzed
7.2EPSS 0.001
CVE-2026-24085
Stack-based Buffer Overflow in Display
Published 2026-06-01 · Analyzed
7.2EPSS 0.001
CVE-2021-30278
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2022-01-03 · Modified
7.1EPSS 0.001
CVE-2021-1935
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-09-09 · Modified
7.1EPSS 0.001
CVE-2021-30283
Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-01-03 · Modified
7.1EPSS 0.001
CVE-2024-23362
Improper Input Validation in Trusted Execution Environment
Published 2024-09-02 · Analyzed
7.1EPSS 0.001
CVE-2024-43065
Exposed Dangerous Method or Function in HLOS
Published 2025-04-07 · Analyzed
7.1EPSS 0.001
CVE-2022-22076
Cryptographic issue in Core
Published 2023-06-06 · Modified
7.1EPSS 0.001
CVE-2022-40523
Information exposure in Kernel
Published 2023-06-06 · Modified
7.1EPSS 0.001
CVE-2023-21626
Improper Authentication in HLOS.
Published 2023-08-08 · Modified
7.1EPSS 0.001
CVE-2024-21462
Buffer Over-read in TZ Secure OS
Published 2024-07-01 · Modified
7.1EPSS 0.001
CVE-2022-33289
Improper validation of array index in Modem
Published 2023-04-04 · Modified
6.8EPSS 0.002
CVE-2023-21629
Double Free in Modem
Published 2023-07-04 · Modified
6.8EPSS 0.002
CVE-2024-33016
Improper Restriction of Operations within the Bounds of a Memory Buffer in Storage
Published 2024-09-02 · Analyzed
6.8EPSS 0.002
CVE-2022-25653
Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-09-16 · Modified
6.8EPSS 0.001
CVE-2022-25676
Information disclosure in video due to buffer over-read while parsing avi files in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-11-15 · Modified
6.8EPSS 0.001
CVE-2022-40518
Buffer overread in Core
Published 2023-01-06 · Modified
6.8EPSS 0.001
CVE-2022-40519
Buffer over-read in Core
Published 2023-01-06 · Modified
6.8EPSS 0.001
CVE-2021-30266
Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-11-12 · Modified
6.7EPSS 0.002
CVE-2021-35118
An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-35120
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-06-14 · Modified
6.7EPSS 0.002
CVE-2021-30264
Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-11-12 · Modified
6.7EPSS 0.002
CVE-2021-35133
Use after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-09-02 · Modified
6.7EPSS 0.001
CVE-2021-30299
Improper Input Validation in Audio
Published 2024-11-22 · Analyzed
6.7EPSS 0.001
CVE-2026-24076
Buffer Copy Without Checking Size of Input in Bluetooth HOST
Published 2026-08-04 · Analyzed
6.7EPSS 0.001
CVE-2021-30313
Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-01-13 · Modified
6.7EPSS 0.001
CVE-2025-47319
Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS
Published 2025-12-18 · Analyzed
6.7EPSS 0.001
CVE-2025-47334
Buffer Copy Without Checking Size of Input in Camera Driver
Published 2026-01-06 · Analyzed
6.7EPSS 0.001
CVE-2025-47335
Buffer Copy Without Checking Size of Input in Camera Driver
Published 2026-01-06 · Analyzed
6.7EPSS 0.001
CVE-2025-47337
Use After Free in Camera Driver
Published 2026-01-06 · Analyzed
6.7EPSS 0.001
CVE-2025-59611
Out-of-bounds Write in Core Services
Published 2026-06-01 · Analyzed
6.7EPSS 0.001
CVE-2025-59613
Stack-based Buffer Overflow in Windows Compute
Published 2026-06-01 · Analyzed
6.7EPSS 0.001
CVE-2025-59612
Stack-based Buffer Overflow in Windows Compute
Published 2026-06-01 · Analyzed
6.7EPSS 0.001
CVE-2025-47344
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
Published 2026-01-06 · Analyzed
6.7EPSS 0.001
CVE-2025-47333
Use After Free in HLOS
Published 2026-01-06 · Analyzed
6.6EPSS 0.001
CVE-2021-1960
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-09-09 · Modified
6.5EPSS 0.002
← Prev14 / 15Next →