Qualcomm
Qualcomm Sd778g Firmware: vulnerabilities and CVEs
Qualcomm Sd778g Firmware has 284 published vulnerabilities, 0 of them in the last 12 months. 40 are rated critical and 1 are listed by CISA as actively exploited.
CVEs284
Last 12 months0
Critical40
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22071 | High (7.8) | 0.46% | ⚠ Active exploitation | Jun 14, 2022 | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21664 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory Corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-21662 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-21646 | High (7.5) | 0.38% | — | Sep 5, 2023 | Transient DOS in Modem while processing invalid System Information Block 1. |
| CVE-2023-28537 | High (7.8) | 0.12% | — | Aug 8, 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. |
| CVE-2023-22666 | High (7.8) | 0.12% | — | Aug 8, 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21652 | High (7.1) | 0.10% | — | Aug 8, 2023 | Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use. |
| CVE-2023-21651 | High (7.8) | 0.12% | — | Aug 8, 2023 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. |
| CVE-2023-21626 | High (7.1) | 0.11% | — | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Critical (9.8) | 0.43% | — | Aug 8, 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2023-21630 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. |
| CVE-2022-40532 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-40503 | High (7.5) | 0.41% | — | Apr 13, 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
| CVE-2022-33302 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33289 | Medium (6.8) | 0.19% | — | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-33288 | High (8.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. |
| CVE-2022-33270 | Medium (5.9) | 0.28% | — | Apr 13, 2023 | Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. |
| CVE-2022-33231 | High (7.8) | 0.08% | — | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. |
| CVE-2022-40537 | Critical (9.8) | 0.36% | — | Mar 10, 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40531 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40530 | High (7.8) | 0.13% | — | Mar 10, 2023 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. |
| CVE-2022-40527 | High (7.5) | 0.41% | — | Mar 10, 2023 | Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. |
| CVE-2022-40515 | Critical (9.8) | 0.33% | — | Mar 10, 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33278 | High (7.8) | 0.12% | — | Mar 10, 2023 | Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. |
| CVE-2022-33272 | High (7.5) | 0.41% | — | Mar 10, 2023 | Transient DOS in modem due to reachable assertion. |
| CVE-2022-33257 | High (7) | 0.09% | — | Mar 10, 2023 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. |
| CVE-2022-33256 | Critical (9.8) | 0.53% | — | Mar 10, 2023 | Memory corruption due to improper validation of array index in Multi-mode call processor. |
| CVE-2022-33254 | High (7.5) | 0.41% | — | Mar 10, 2023 | Transient DOS due to reachable assertion in Modem while processing SIB1 Message. |
| CVE-2022-33250 | High (7.5) | 0.41% | — | Mar 10, 2023 | Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover. |
| CVE-2022-33244 | High (7.5) | 0.41% | — | Mar 10, 2023 | Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout |
| CVE-2022-33242 | High (7.8) | 0.14% | — | Mar 10, 2023 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.