Vulnerabilities > Qualcomm > Sd695 Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-06-14 CVE-2021-35073 Reachable Assertion vulnerability in Qualcomm products
Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-617
7.8
2022-06-14 CVE-2021-35076 NULL Pointer Dereference vulnerability in Qualcomm products
Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-476
7.8
2022-06-14 CVE-2021-35078 Memory Leak vulnerability in Qualcomm products
Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
network
low complexity
qualcomm CWE-401
7.8
2022-06-14 CVE-2021-35079 Improper Preservation of Permissions vulnerability in Qualcomm products
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-281
2.1
2022-06-14 CVE-2021-35080 Information Exposure vulnerability in Qualcomm products
Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
low complexity
qualcomm CWE-200
4.9
2022-06-14 CVE-2021-35083 Out-of-bounds Read vulnerability in Qualcomm products
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
network
low complexity
qualcomm CWE-125
critical
9.4
2022-06-14 CVE-2021-35084 Out-of-bounds Read vulnerability in Qualcomm products
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
local
low complexity
qualcomm CWE-125
3.6
2022-06-14 CVE-2021-35085 Out-of-bounds Read vulnerability in Qualcomm products
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
local
low complexity
qualcomm CWE-125
3.6
2022-06-14 CVE-2021-35086 Out-of-bounds Read vulnerability in Qualcomm products
Possible buffer over read due to improper validation of SIB type when processing a NR system Information message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-125
7.8
2022-06-14 CVE-2021-35087 NULL Pointer Dereference vulnerability in Qualcomm products
Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile
network
low complexity
qualcomm CWE-476
7.8