« Back to list

Qualcomm

Qualcomm Msm8956 Firmware: vulnerabilities and CVEs

Qualcomm Msm8956 Firmware has 21 published vulnerabilities, 0 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.

CVEs21
Last 12 months0
Critical6
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-40515Critical (9.8)0.33%—Mar 10, 2023
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
CVE-2022-33213High (8.8)0.41%—Mar 10, 2023
Memory corruption in modem due to buffer overflow while processing a PPP packet
CVE-2022-25705High (7.8)0.13%—Mar 10, 2023
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
CVE-2022-25694High (7.8)0.12%—Mar 10, 2023
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
CVE-2022-22075Medium (5.5)0.12%—Mar 10, 2023
Information Disclosure in Graphics during GPU context switch.
CVE-2022-33233High (7.8)0.12%—Feb 12, 2023
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
CVE-2022-22088High (8.8)0.51%—Jan 9, 2023
Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote
CVE-2022-25695High (7.8)0.13%—Dec 13, 2022
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2022-25682High (7.8)0.13%—Dec 13, 2022
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2022-25743High (7.8)0.15%—Nov 15, 2022
Memory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
CVE-2022-25724High (7.8)0.12%—Nov 15, 2022
Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2022-25720Critical (9.8)0.46%—Oct 19, 2022
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2022-25719Critical (9.1)0.50%—Oct 19, 2022
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2022-25718Critical (9.8)0.45%—Oct 19, 2022
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,…
CVE-2022-25687Critical (9.8)0.35%—Oct 19, 2022
memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
CVE-2022-25664Medium (5.5)0.18%—Oct 19, 2022
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
CVE-2021-1924Medium (5.5)0.17%—Nov 12, 2021
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…
CVE-2021-1909High (7.8)0.16%—Sep 9, 2021
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer…
CVE-2020-11269High (8.8)0.29%—Feb 22, 2021
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…
CVE-2020-11170Critical (9.8)0.83%—Feb 22, 2021
Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2020-11207High (7.8)1.5%—Nov 12, 2020
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052,…

Other products by Qualcomm