Qualcomm
Qualcomm Mdm9607 Firmware: vulnerabilities and CVEs
Qualcomm Mdm9607 Firmware has 736 published vulnerabilities, 0 of them in the last 12 months. 263 are rated critical and 2 are listed by CISA as actively exploited.
CVEs736
Last 12 months0
Critical263
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1906 | Medium (5.5) | 0.52% | ⚠ Active exploitation | May 7, 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | High (7.8) | 1.5% | ⚠ Active exploitation | May 7, 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5852 | High (7.8) | 0.12% | — | Nov 26, 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | High (7.8) | 0.11% | — | Nov 26, 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2018-11922 | Medium (5.5) | 0.23% | — | Nov 26, 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-15832 | High (7.8) | 0.12% | — | Nov 26, 2024 | Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW |
| CVE-2016-10394 | High (7.8) | 0.10% | — | Nov 26, 2024 | Initial xbl_sec revision does not have all the debug policy features and critical checks. |
| CVE-2017-9711 | High (7.8) | 0.12% | — | Nov 22, 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2023-21626 | High (7.1) | 0.11% | — | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Critical (9.8) | 0.43% | — | Aug 8, 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40537 | Critical (9.8) | 0.36% | — | Mar 10, 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40531 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40515 | Critical (9.8) | 0.33% | — | Mar 10, 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33213 | High (8.8) | 0.41% | — | Mar 10, 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | High (7.8) | 0.13% | — | Mar 10, 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-25655 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-22075 | Medium (5.5) | 0.12% | — | Mar 10, 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-40512 | High (7.5) | 0.42% | — | Feb 12, 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
| CVE-2022-33233 | High (7.8) | 0.12% | — | Feb 12, 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-33229 | High (7.5) | 0.38% | — | Feb 12, 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. |
| CVE-2022-25738 | High (7.5) | 0.38% | — | Feb 12, 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received |
| CVE-2022-25735 | High (7.5) | 0.41% | — | Feb 12, 2023 | Denial of service in modem due to missing null check while processing TCP or UDP packets from server |
| CVE-2022-25734 | High (7.5) | 0.41% | — | Feb 12, 2023 | Denial of service in modem due to missing null check while processing IP packets with padding |
| CVE-2022-25733 | High (7.5) | 0.41% | — | Feb 12, 2023 | Denial of service in modem due to null pointer dereference while processing DNS packets |
| CVE-2022-25732 | High (7.5) | 0.38% | — | Feb 12, 2023 | Information disclosure in modem due to buffer over read in dns client due to missing length check |
| CVE-2022-25728 | High (7.5) | 0.38% | — | Feb 12, 2023 | Information disclosure in modem due to buffer over-read while processing response from DNS server |
| CVE-2022-33299 | High (7.5) | 0.38% | — | Jan 9, 2023 | Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. |
| CVE-2022-33290 | High (7.5) | 0.38% | — | Jan 9, 2023 | Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. |
| CVE-2022-33286 | Medium (6.5) | 0.38% | — | Jan 9, 2023 | Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. |
| CVE-2022-33285 | Medium (6.5) | 0.38% | — | Jan 9, 2023 | Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
| CVE-2022-33266 | High (7.8) | 0.11% | — | Jan 9, 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.