Vulnerabilities > Qualcomm > Snapdragon 670 Mobile Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-05-06 CVE-2024-49835 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while reading secure file.
local
low complexity
qualcomm CWE-787
7.8
2025-05-06 CVE-2024-49841 Detection of Error Condition Without Action vulnerability in Qualcomm products
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
local
low complexity
qualcomm CWE-390
7.8
2025-05-06 CVE-2024-49842 Improper Access Control vulnerability in Qualcomm products
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
local
low complexity
qualcomm CWE-284
7.8
2025-05-06 CVE-2024-49844 Improper Input Validation vulnerability in Qualcomm products
Memory corruption while triggering commands in the PlayReady Trusted application.
local
low complexity
qualcomm CWE-20
7.8
2025-05-06 CVE-2025-21453 Use After Free vulnerability in Qualcomm products
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
local
low complexity
qualcomm CWE-416
7.8
2025-02-03 CVE-2024-38420 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while configuring a Hypervisor based input virtual device.
local
low complexity
qualcomm CWE-787
7.8
2024-09-02 CVE-2024-33052 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption when user provides data for FM HCI command control operations.
local
low complexity
qualcomm CWE-787
7.8
2024-09-02 CVE-2024-33060 Use After Free vulnerability in Qualcomm products
Memory corruption when two threads try to map and unmap a single node simultaneously.
local
low complexity
qualcomm CWE-416
7.8
2024-06-03 CVE-2023-43538 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
local
low complexity
qualcomm CWE-120
7.8
2024-06-03 CVE-2023-43551 Improper Authentication vulnerability in Qualcomm products
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
network
low complexity
qualcomm CWE-287
7.5