Vulnerabilities > Qualcomm > SD 8CX Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-05-06 CVE-2024-49841 Detection of Error Condition Without Action vulnerability in Qualcomm products
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
local
low complexity
qualcomm CWE-390
7.8
2025-05-06 CVE-2024-49842 Improper Access Control vulnerability in Qualcomm products
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
local
low complexity
qualcomm CWE-284
7.8
2025-03-03 CVE-2024-43056 Buffer Over-read vulnerability in Qualcomm products
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
local
low complexity
qualcomm CWE-126
6.5
2025-02-03 CVE-2024-38420 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while configuring a Hypervisor based input virtual device.
local
low complexity
qualcomm CWE-787
7.8
2024-12-02 CVE-2024-33044 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
local
low complexity
qualcomm CWE-129
7.8
2024-12-02 CVE-2024-33056 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
local
low complexity
qualcomm CWE-125
7.8
2024-09-02 CVE-2024-33051 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
network
low complexity
qualcomm CWE-125
7.5
2024-07-01 CVE-2024-21462 Out-of-bounds Read vulnerability in Qualcomm products
Transient DOS while loading the TA ELF file.
local
low complexity
qualcomm CWE-125
5.5
2024-07-01 CVE-2024-21465 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption while processing key blob passed by the user.
local
low complexity
qualcomm CWE-125
7.8
2024-07-01 CVE-2024-21469 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
local
low complexity
qualcomm CWE-787
7.8