VendorsQualcommsd835_firmwareall versions
Vulnerabilities

Qualcomm SD835 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

255CVEs
CVE-2023-28567
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28558
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2022-33298
Use after free in Modem
Published 2023-04-04 · Modified
7.8EPSS 0.001
CVE-2023-21633
Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-21637
Improper Restrictions of Operations within the Bounds of a Memory Buffer in Linux
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2022-25717
Use-After-Free Issue in Display
Published 2023-01-06 · Modified
7.8EPSS 0.001
CVE-2022-33227
Double free in Linux-Android
Published 2023-06-06 · Modified
7.8EPSS 0.001
CVE-2022-33266
Integer overflow to buffer overflow in Audio
Published 2023-01-06 · Modified
7.8EPSS 0.001
CVE-2022-33296
Integer overflow to buffer overflow in Modem
Published 2023-04-04 · Modified
7.8EPSS 0.001
CVE-2023-28539
Buffer Copy Without Checking Size of Input in WLAN Host
Published 2023-10-03 · Modified
7.8EPSS 0.001
CVE-2023-28546
Buffer Copy Without Checking Size of Input in SPS Applications
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2023-33018
Integer Overflow to Buffer Overflow in User Identity Module
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2023-33059
Buffer Copy Without Checking Size of Input in Audio
Published 2023-11-07 · Modified
7.8EPSS 0.001
CVE-2018-11816
Use After Free in Video
Published 2024-11-26 · Analyzed
7.8EPSS 0.001
CVE-2023-33120
Use After Free in Audio
Published 2024-01-02 · Modified
7.8EPSS 0.001
CVE-2023-33067
Use of Out-of-range Pointer Offset in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-33077
Buffer Copy Without Checking Size of Input in HLOS
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-33068
Buffer Copy Without Checking Size of Input in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2023-33069
Buffer Copy Without Checking Size of Input in Audio
Published 2024-02-06 · Modified
7.8EPSS 0.001
CVE-2024-45562
Use After Free in HLOS
Published 2025-05-06 · Analyzed
7.8EPSS 0.001
CVE-2025-21453
Use After Free in GPS HLOS Driver
Published 2025-05-06 · Analyzed
7.8EPSS 0.001
CVE-2024-38423
Buffer Copy Without Checking Size of Input in Graphics Linux
Published 2024-11-04 · Analyzed
7.8EPSS 0.001
CVE-2024-38422
Integer Overflow to Buffer Overflow in Audio
Published 2024-11-04 · Analyzed
7.8EPSS 0.001
CVE-2021-35116
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-06-14 · Modified
7.7EPSS 0.002
CVE-2018-11291
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDM630, SDM632, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016, cryptographic issues due to the random number generator was not a strong one in NAN.
Published 2018-09-20 · Modified
7.5EPSS 0.008
CVE-2022-25736
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2022-10-19 · Modified
7.5EPSS 0.008
CVE-2018-5837
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016, MAC address randomization performed during probe requests is not done properly due to a flawed RNG which produced repeating output much earlier than expected.
Published 2018-09-20 · Modified
7.5EPSS 0.006
CVE-2021-1970
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1907
Possible buffer overflow due to lack of length check in BA request in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1938
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1943
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1945
Possible out of bound read due to lack of length check of Bandwidth-NSS IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1953
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1955
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1964
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-07-13 · Modified
7.5EPSS 0.006
CVE-2021-1974
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-09-09 · Modified
7.5EPSS 0.006
CVE-2021-1914
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-09-08 · Modified
7.5EPSS 0.006
CVE-2023-28588
Integer Overflow or Wraparound in Bluetooth Host
Published 2023-12-05 · Modified
7.5EPSS 0.005
CVE-2022-25669
Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-09-16 · Modified
7.5EPSS 0.005
CVE-2022-25690
Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published 2022-09-16 · Modified
7.5EPSS 0.004
← Prev5 / 7Next →