Vulnerabilities > Qualcomm

DATE CVE VULNERABILITY TITLE RISK
2021-06-09 CVE-2020-11260 Use of Uninitialized Resource vulnerability in Qualcomm products
An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-908
8.4
2021-06-09 CVE-2020-11261 Improper Input Validation vulnerability in Qualcomm products
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-20
7.8
2021-06-09 CVE-2020-11262 Use After Free vulnerability in Qualcomm products
A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue.
local
high complexity
qualcomm CWE-416
7.0
2021-06-09 CVE-2020-11265 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-125
5.5
2021-06-09 CVE-2020-11266 Unspecified vulnerability in Qualcomm products
Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm
6.5
2021-05-07 CVE-2020-11254 NULL Pointer Dereference vulnerability in Qualcomm products
Memory corruption during buffer allocation due to dereferencing session ctx pointer without checking if pointer is valid in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
local
low complexity
qualcomm CWE-476
5.5
2021-05-07 CVE-2020-11268 Improper Input Validation vulnerability in Qualcomm products
Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile
network
low complexity
qualcomm CWE-20
7.5
2021-05-07 CVE-2020-11273 NULL Pointer Dereference vulnerability in Qualcomm products
Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null pointer access when histogram binning info is missing due to lack of null check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
network
low complexity
qualcomm CWE-476
7.5
2021-05-07 CVE-2020-11274 Reachable Assertion vulnerability in Qualcomm products
Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-617
7.5
2021-05-07 CVE-2020-11279 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
network
low complexity
qualcomm CWE-190
critical
9.8