VendorsQualcommsm4125_firmwareall versions
Vulnerabilities

Qualcomm SM4125 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

259CVEs
CVE-2021-35078
Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published 2022-06-14 · Modified
7.8EPSS 0.004
CVE-2020-11228
Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-03-17 · Modified
7.8EPSS 0.002
CVE-2020-11127
u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validation of security metadata while processing objects to be loaded' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9205, QCM4290, QCS405, QCS410, QCS4290, QCS610, QSM8250, SA415M, SA515M, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SC8180X, SC8180X+SDX55, SC8180XP, SDA640, SDA845, SDA855, SDM1000, SDM640, SDM830, SDM845, SDM850, SDX24, SDX50M, SDX55, SDX55M, SM4125, SM4250, SM4250P, SM6115, SM6115P, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR2130, SXR2130P
Published 2020-11-12 · Modified
7.8EPSS 0.002
CVE-2020-11304
Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-06-09 · Modified
7.8EPSS 0.002
CVE-2020-11306
Possible integer overflow in RPMB counter due to lack of length check on user provided data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-06-09 · Modified
7.8EPSS 0.002
CVE-2021-1959
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-10-20 · Modified
7.8EPSS 0.002
CVE-2020-11194
Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published 2021-02-22 · Modified
7.8EPSS 0.002
CVE-2021-35072
Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-06-14 · Modified
7.8EPSS 0.002
CVE-2021-1952
Possible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
Published 2021-09-09 · Modified
7.8EPSS 0.002
CVE-2023-33017
Buffer Copy Without Checking Size of Input in Boot
Published 2023-12-05 · Modified
7.8EPSS 0.002
CVE-2023-28587
Improper Restriction of Operations within the Bounds of a Memory Buffer in BT Controller
Published 2023-12-05 · Modified
7.8EPSS 0.002
CVE-2023-33079
Use of Out-of-range Pointer Offset in Audio
Published 2023-12-05 · Modified
7.8EPSS 0.002
CVE-2021-30254
Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30255
Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-1973
A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-30259
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published 2021-11-12 · Modified
7.8EPSS 0.002
CVE-2021-35094
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published 2022-06-14 · Modified
7.8EPSS 0.002
CVE-2021-1923
Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT
Published 2021-09-08 · Modified
7.8EPSS 0.002
CVE-2023-33055
Buffer Copy Without Checking Size of Input in Audio
Published 2023-11-07 · Modified
7.8EPSS 0.001
CVE-2022-33242
Improper authentication in Qualcomm IPC
Published 2023-03-07 · Modified
7.8EPSS 0.001
CVE-2020-11298
While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memory buffers used by HLOS Invoke Call to secure kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Published 2021-06-09 · Modified
7.8EPSS 0.001
CVE-2023-28556
Improper Authorization in HLOS
Published 2023-11-07 · Modified
7.8EPSS 0.001
CVE-2022-22070
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published 2022-09-02 · Modified
7.8EPSS 0.001
CVE-2022-33278
Buffer copy without checking the size of input in HLOS
Published 2023-03-07 · Modified
7.8EPSS 0.001
CVE-2023-28550
Improper Restriction of Operations within the Bounds of a Memory Buffer in MPP Performance
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2023-28551
Improper Restriction of Operations within the Bounds of a Memory Buffer in UTILS
Published 2023-12-05 · Modified
7.8EPSS 0.001
CVE-2025-21424
Use After Free in NPU
Published 2025-03-03 · Analyzed
7.8EPSS 0.001
CVE-2023-28544
Buffer Copy without Checking the Size of Input in WLAN Firmware
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28557
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-21657
Improper Input Validation in Audio
Published 2023-06-06 · Modified
7.8EPSS 0.001
CVE-2023-21670
Improper Access control in GPU Subsystem
Published 2023-06-06 · Modified
7.8EPSS 0.001
CVE-2023-22386
Buffer Copy Without Checking Size of Input in WLAN HOST
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-28560
Buffer Copy Without Checking Size of Input in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-22387
Use of Out-of-range Pointer Offset in Qualcomm IPC
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-24854
Stack-based Buffer Overflow in WLAN HOST
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-28542
Buffer Over-read in WLAN HOST
Published 2023-07-04 · Modified
7.8EPSS 0.001
CVE-2023-28564
Use of Out-of-range Pointer Offset in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28565
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28558
Improper Validation of Array Index in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
CVE-2023-28559
Buffer Copy Without Checking Size of Input in WLAN HAL
Published 2023-09-05 · Modified
7.8EPSS 0.001
← Prev4 / 7Next →