Vulnerabilities > Qualcomm > Snapdragon X35 5G Modem RF Firmware

DATE CVE VULNERABILITY TITLE RISK
2025-02-03 CVE-2024-38420 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption while configuring a Hypervisor based input virtual device.
local
low complexity
qualcomm CWE-787
7.8
2025-02-03 CVE-2024-45584 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
local
low complexity
qualcomm CWE-119
7.8
2025-02-03 CVE-2024-49838 Out-of-bounds Read vulnerability in Qualcomm products
Information disclosure while parsing the OCI IE with invalid length.
network
low complexity
qualcomm CWE-125
7.5
2025-01-06 CVE-2024-45553 Use After Free vulnerability in Qualcomm products
Memory corruption can occur when process-specific maps are added to the global list.
local
low complexity
qualcomm CWE-416
7.8
2024-09-02 CVE-2024-38402 Use After Free vulnerability in Qualcomm products
Memory corruption while processing IOCTL call for getting group info.
local
low complexity
qualcomm CWE-416
7.8
2024-05-06 CVE-2023-33119 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
local
high complexity
qualcomm CWE-367
7.0
2024-05-06 CVE-2023-43530 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption in HLOS while checking for the storage type.
local
low complexity
qualcomm CWE-190
7.8
2024-05-06 CVE-2023-43531 Access of Uninitialized Pointer vulnerability in Qualcomm products
Memory corruption while verifying the serialized header when the key pairs are generated.
local
low complexity
qualcomm CWE-824
7.8
2024-05-06 CVE-2024-21480 Classic Buffer Overflow vulnerability in Qualcomm products
Memory corruption while playing audio file having large-sized input buffer.
network
low complexity
qualcomm CWE-120
critical
9.8
2024-04-01 CVE-2023-28547 Out-of-bounds Write vulnerability in Qualcomm products
Memory corruption in SPS Application while requesting for public key in sorter TA.
local
low complexity
qualcomm CWE-787
7.8