Vulnerabilities > Qualcomm > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-02 CVE-2021-35108 Improper Check for Unusual or Exceptional Conditions vulnerability in Qualcomm products
Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-754
6.8
2022-09-02 CVE-2021-35109 Improper Input Validation vulnerability in Qualcomm products
Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Snapdragon Mobile
low complexity
qualcomm CWE-20
6.8
2022-09-02 CVE-2021-35113 Improper Verification of Cryptographic Signature vulnerability in Qualcomm products
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
low complexity
qualcomm CWE-347
6.8
2022-09-02 CVE-2021-35133 Use After Free vulnerability in Qualcomm products
Use after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-416
6.7
2022-09-02 CVE-2021-35135 NULL Pointer Dereference vulnerability in Qualcomm products
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
local
low complexity
qualcomm CWE-476
5.5
2022-09-02 CVE-2022-22101 Resource Exhaustion vulnerability in Qualcomm products
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto
local
low complexity
qualcomm CWE-400
5.5
2022-06-14 CVE-2021-30327 Classic Buffer Overflow vulnerability in Qualcomm products
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music
low complexity
qualcomm CWE-120
6.8
2022-06-14 CVE-2021-30338 Improper Input Validation vulnerability in Qualcomm Sd850 Firmware and Sdxr1 Firmware
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute
local
low complexity
qualcomm CWE-20
5.5
2022-06-14 CVE-2021-30339 Unspecified vulnerability in Qualcomm products
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm
5.5
2022-06-14 CVE-2021-30342 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
network
high complexity
qualcomm CWE-367
5.9