Qualcomm
Qualcomm Sd210 Firmware: vulnerabilities and CVEs
Qualcomm Sd210 Firmware has 189 published vulnerabilities, 0 of them in the last 12 months. 44 are rated critical and 3 are listed by CISA as actively exploited.
CVEs189
Last 12 months0
Critical44
Actively exploited3
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11261 | High (7.8) | 1.6% | ⚠ Active exploitation | Jun 9, 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Medium (5.5) | 0.52% | ⚠ Active exploitation | May 7, 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | High (7.8) | 1.5% | ⚠ Active exploitation | May 7, 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30299 | Medium (6.7) | 0.12% | — | Nov 22, 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. |
| CVE-2023-28575 | High (7.8) | 0.12% | — | Aug 8, 2023 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. |
| CVE-2023-28537 | High (7.8) | 0.12% | — | Aug 8, 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. |
| CVE-2023-22666 | High (7.8) | 0.12% | — | Aug 8, 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21626 | High (7.1) | 0.11% | — | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2023-21625 | High (7.5) | 0.35% | — | Aug 8, 2023 | Information disclosure in Network Services due to buffer over-read while the device receives DNS response. |
| CVE-2022-40510 | Critical (9.8) | 0.43% | — | Aug 8, 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40537 | Critical (9.8) | 0.36% | — | Mar 10, 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40515 | Critical (9.8) | 0.33% | — | Mar 10, 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33213 | High (8.8) | 0.41% | — | Mar 10, 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | High (7.8) | 0.13% | — | Mar 10, 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-22075 | Medium (5.5) | 0.12% | — | Mar 10, 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-33248 | High (7.8) | 0.13% | — | Feb 12, 2023 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. |
| CVE-2022-33243 | High (7.8) | 0.11% | — | Feb 12, 2023 | Memory corruption due to improper access control in Qualcomm IPC. |
| CVE-2022-33233 | High (7.8) | 0.12% | — | Feb 12, 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-33225 | High (7.8) | 0.12% | — | Feb 12, 2023 | Memory corruption due to use after free in trusted application environment. |
| CVE-2022-33266 | High (7.8) | 0.11% | — | Jan 9, 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
| CVE-2022-33255 | Medium (6.5) | 0.41% | — | Jan 9, 2023 | Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device. |
| CVE-2022-25722 | Medium (5.5) | 0.11% | — | Jan 9, 2023 | Information exposure in DSP services due to improper handling of freeing memory |
| CVE-2022-25721 | High (7.8) | 0.11% | — | Jan 9, 2023 | Memory corruption in video driver due to type confusion error during video playback |
| CVE-2022-25717 | High (7.8) | 0.11% | — | Jan 9, 2023 | Memory corruption in display due to double free while allocating frame buffer memory |
| CVE-2022-25715 | High (7.8) | 0.11% | — | Jan 9, 2023 | Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields |
| CVE-2022-22088 | High (8.8) | 0.51% | — | Jan 9, 2023 | Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote |
| CVE-2022-22079 | Medium (4.6) | 0.17% | — | Jan 9, 2023 | Denial of service while processing fastboot flash command on mmc due to buffer over read |
| CVE-2022-33268 | High (8.1) | 0.47% | — | Dec 13, 2022 | Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2022-25712 | High (7.8) | 0.13% | — | Dec 13, 2022 | Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25711 | High (7.8) | 0.13% | — | Dec 13, 2022 | Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25702 | High (7.5) | 0.42% | — | Dec 13, 2022 | Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25695 | High (7.8) | 0.13% | — | Dec 13, 2022 | Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.