qualcomm security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect qualcomm products.
Vulnios monitors qualcomm CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent qualcomm security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-11136 — qualcomm — apq8009, apq8009w
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory requirement in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna
criticalCVE-2020-11136Critical Vulnerability: CVE-2020-11140 — qualcomm — apq8017, apq8037
Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdra
criticalCVE-2020-11140Critical Vulnerability: CVE-2020-3686 — qualcomm — apq8009, apq8009w
Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdrag
criticalCVE-2020-3686Critical Vulnerability: CVE-2020-11143 — qualcomm — apq8009, apq8017
Out of bound memory access during music playback with modified content due to copying data without checking destination buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna
criticalCVE-2020-11143Critical Vulnerability: CVE-2020-3691 — qualcomm — apq8009, apq8009w
Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd
criticalCVE-2020-3691Critical Vulnerability: CVE-2020-11212 — qualcomm — apq8009, apq8016
Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics
criticalCVE-2020-11212Critical Vulnerability: CVE-2020-11138 — qualcomm — apq8009, apq8009w
Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi
criticalCVE-2020-11138Critical Vulnerability: CVE-2020-11137 — qualcomm — apq8009, apq8009w
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Compu
criticalCVE-2020-11137Critical Vulnerability: CVE-2020-11197 — qualcomm — apq8009, apq8009w
Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with invalid data in Snapdragon Auto, Snapdragon Compute, Sna
criticalCVE-2020-11197Critical Vulnerability: CVE-2020-11216 — qualcomm — apq8009, apq8009w
Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon
criticalCVE-2020-11216Critical Vulnerability: CVE-2020-11225 — qualcomm — apq8064au, apq8096au
Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics
criticalCVE-2020-11225Critical Vulnerability: CVE-2020-11213 — qualcomm — apq8009, apq8009w
Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consume
criticalCVE-2020-11213Critical Vulnerability: CVE-2020-11215 — qualcomm — aqt1000, ar8031
An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electr
criticalCVE-2020-11215Critical Vulnerability: CVE-2020-11167 — qualcomm — apq8009w, apq8017
Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum
criticalCVE-2020-11167Critical Vulnerability: CVE-2020-11144 — qualcomm — apq8009, apq8009w
Buffer over-read while UE process invalid DL ROHC packet for decompression due to lack of check of size of compresses packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon
criticalCVE-2020-11144Critical Vulnerability: CVE-2020-11193 — qualcomm — apq8009_firmware, apq8009
u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial
criticalCVE-2020-11193Critical Vulnerability: CVE-2020-3639 — qualcomm — apq8009_firmware, apq8009
u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum
criticalCVE-2020-3639Critical Vulnerability: CVE-2020-11196 — qualcomm — apq8009_firmware, apq8009
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industria
criticalCVE-2020-11196Critical Vulnerability: CVE-2020-11184 — qualcomm — qcm4290_firmware, qcm4290
u'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS
criticalCVE-2020-11184Critical Vulnerability: CVE-2020-11168 — qualcomm — apq8009w_firmware, apq8009w
u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snap
criticalCVE-2020-11168Critical Vulnerability: CVE-2020-3673 — qualcomm — agatti_firmware, agatti
u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdragon Compute, Snapdrago
criticalCVE-2020-3673Critical Vulnerability: CVE-2020-11169 — qualcomm — apq8009_firmware, apq8009
u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connec
criticalCVE-2020-11169Critical Vulnerability: CVE-2020-3692 — qualcomm — agatti_firmware, agatti
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Comput
criticalCVE-2020-3692Critical Vulnerability: CVE-2020-3670 — qualcomm — agatti_firmware, agatti
u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Information Element(IEI) NAS message container' in Snapdragon Auto, Snapdragon Compute, S
criticalCVE-2020-3670Critical Vulnerability: CVE-2020-3703 — qualcomm — apq8053_firmware, apq8053
u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(This CVE is equivalent to Link Layer Length Overfow
criticalCVE-2020-3703Critical Vulnerability: CVE-2020-11153 — qualcomm — apq8053_firmware, apq8053
u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
criticalCVE-2020-11153Critical Vulnerability: CVE-2020-3657 — qualcomm — apq8009_firmware, apq8009
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdr
criticalCVE-2020-3657Critical Vulnerability: CVE-2020-11172 — qualcomm — ipq4019_firmware, ipq4019
u'fscanf reads a string from a file and stores its contents on a statically allocated stack memory which leads to stack overflow' in Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018,
criticalCVE-2020-11172Critical Vulnerability: CVE-2020-3654 — qualcomm — agatti_firmware, agatti
u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago
criticalCVE-2020-3654Critical Vulnerability: CVE-2019-14052 — qualcomm — apq8009_firmware, apq8009
u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Ind
criticalCVE-2019-14052Critical Vulnerability: CVE-2020-3668 — qualcomm — ipq6018_firmware, ipq6018
u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrago
criticalCVE-2020-3668Critical Vulnerability: CVE-2020-3634 — qualcomm — apq8053_firmware, apq8053
u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,
criticalCVE-2020-3634Critical Vulnerability: CVE-2020-3675 — qualcomm — ipq5018_firmware, ipq5018
u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Cons
criticalCVE-2020-3675Critical Vulnerability: CVE-2020-11117 — qualcomm — ipq4019_firmware, ipq4019
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity,
criticalCVE-2020-11117Critical Vulnerability: CVE-2020-3669 — qualcomm — apq8098_firmware, apq8098
u'Buffer Overflow issue in WLAN tcp ip verification due to usage of out of range pointer offset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connec
criticalCVE-2020-3669Critical Vulnerability: CVE-2020-3667 — qualcomm — apq8098_firmware, apq8098
u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum
criticalCVE-2020-3667Critical Vulnerability: CVE-2020-11116 — qualcomm — apq8009_firmware, apq8009
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connec
criticalCVE-2020-11116Critical Vulnerability: CVE-2020-3688 — qualcomm — apq8009_firmware, apq8009
Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT
criticalCVE-2020-3688Critical Vulnerability: CVE-2020-3698 — qualcomm — apq8009_firmware, apq8009
Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Con
criticalCVE-2020-3698Critical Vulnerability: CVE-2020-3681 — qualcomm
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.
criticalCVE-2020-3681Critical Vulnerability: CVE-2020-3671 — qualcomm — apq8009_firmware, apq8009
Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapd
criticalCVE-2020-3671Critical Vulnerability: CVE-2020-3699 — qualcomm — apq8009_firmware, apq8009
Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics C
criticalCVE-2020-3699Critical Vulnerability: CVE-2020-3660 — qualcomm — apq8009_firmware, apq8009
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrago
criticalCVE-2020-3660Critical Vulnerability: CVE-2020-3663 — qualcomm — apq8009_firmware, apq8009
Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,
criticalCVE-2020-3663Critical Vulnerability: CVE-2019-14073 — qualcomm — apq8009_firmware, apq8009
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow when processing large data or non-standard feedback messages in Sn
criticalCVE-2019-14073Critical Vulnerability: CVE-2020-3658 — qualcomm — apq8009_firmware, apq8009
Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrago
criticalCVE-2020-3658Critical Vulnerability: CVE-2019-14080 — qualcomm — apq8053_firmware, apq8053
Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,
criticalCVE-2019-14080Critical Vulnerability: CVE-2020-3628 — qualcomm — apq8053_firmware, apq8053
Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consumer IOT, Snapdragon Mobile in APQ8053, Rennell, SDX20
criticalCVE-2020-3628Critical Vulnerability: CVE-2020-3661 — qualcomm — apq8009_firmware, apq8009
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAX_UINT32 range due to lack of validation checks in Snapdragon Auto, Snapdragon Compute, Snapdragon
criticalCVE-2020-3661Critical Vulnerability: CVE-2020-3662 — qualcomm — apq8009_firmware, apq8009
Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Ind
criticalCVE-2020-3662Critical Vulnerability: CVE-2019-14062 — qualcomm — apq8009_firmware, apq8009
Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon I
criticalCVE-2019-14062Critical Vulnerability: CVE-2020-3614 — qualcomm — apq8009_firmware, apq8009
Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Elec
criticalCVE-2020-3614Critical Vulnerability: CVE-2020-3633 — qualcomm — apq8009_firmware, apq8009
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sn
criticalCVE-2020-3633Critical Vulnerability: CVE-2020-3641 — qualcomm — apq8009_firmware, apq8009
Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT
criticalCVE-2020-3641Critical Vulnerability: CVE-2020-3615 — qualcomm — apq8009_firmware, apq8009
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper enum values used to check the frame subtype in Snapdr
criticalCVE-2020-3615Critical Vulnerability: CVE-2019-14112 — qualcomm — apq8098_firmware, apq8098
Potential buffer overflow while processing CBF frames due to lack of check of buffer length before copy in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon
criticalCVE-2019-14112Critical Vulnerability: CVE-2019-10588 — qualcomm — apq8009_firmware, apq8009
Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,
criticalCVE-2019-10588Critical Vulnerability: CVE-2019-10622 — qualcomm — apq8009_firmware, apq8009
Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics
criticalCVE-2019-10622Critical Vulnerability: CVE-2019-14132 — qualcomm — qcs605_firmware, qcs605
Buffer over-write when this 0-byte buffer is typecasted to some other structure and hence memory corruption in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SA6155P, SM8150
criticalCVE-2019-14132Critical Vulnerability: CVE-2019-14114 — qualcomm — apq8009_firmware, apq8009
Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer El
criticalCVE-2019-14114
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track qualcomm exposure across your environment
Vulnios automatically cross-references your asset inventory against new qualcomm CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan