« Back to list

Qualcomm

Qualcomm Sd778g Firmware: vulnerabilities and CVEs

Qualcomm Sd778g Firmware has 284 published vulnerabilities, 0 of them in the last 12 months. 40 are rated critical and 1 are listed by CISA as actively exploited.

CVEs284
Last 12 months0
Critical40
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-22071High (7.8)0.46%⚠ Active exploitationJun 14, 2022
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-21664High (7.8)0.12%—Sep 5, 2023
Memory Corruption in Core Platform while printing the response buffer in log.
CVE-2023-21662High (7.8)0.12%—Sep 5, 2023
Memory corruption in Core Platform while printing the response buffer in log.
CVE-2023-21646High (7.5)0.38%—Sep 5, 2023
Transient DOS in Modem while processing invalid System Information Block 1.
CVE-2023-28537High (7.8)0.12%—Aug 8, 2023
Memory corruption while allocating memory in COmxApeDec module in Audio.
CVE-2023-22666High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21652High (7.1)0.10%—Aug 8, 2023
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
CVE-2023-21651High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
CVE-2023-21626High (7.1)0.11%—Aug 8, 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Critical (9.8)0.43%—Aug 8, 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2023-21630High (7.8)0.12%—Apr 13, 2023
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
CVE-2022-40532High (7.8)0.12%—Apr 13, 2023
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
CVE-2022-40503High (7.5)0.41%—Apr 13, 2023
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
CVE-2022-33302High (7.8)0.12%—Apr 13, 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33289Medium (6.8)0.19%—Apr 13, 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
CVE-2022-33288High (8.8)0.12%—Apr 13, 2023
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
CVE-2022-33270Medium (5.9)0.28%—Apr 13, 2023
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
CVE-2022-33231High (7.8)0.08%—Apr 13, 2023
Memory corruption due to double free in core while initializing the encryption key.
CVE-2022-40537Critical (9.8)0.36%—Mar 10, 2023
Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
CVE-2022-40531High (7.8)0.12%—Mar 10, 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
CVE-2022-40530High (7.8)0.13%—Mar 10, 2023
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
CVE-2022-40527High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
CVE-2022-40515Critical (9.8)0.33%—Mar 10, 2023
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
CVE-2022-33278High (7.8)0.12%—Mar 10, 2023
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
CVE-2022-33272High (7.5)0.41%—Mar 10, 2023
Transient DOS in modem due to reachable assertion.
CVE-2022-33257High (7)0.09%—Mar 10, 2023
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
CVE-2022-33256Critical (9.8)0.53%—Mar 10, 2023
Memory corruption due to improper validation of array index in Multi-mode call processor.
CVE-2022-33254High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
CVE-2022-33250High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
CVE-2022-33244High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
CVE-2022-33242High (7.8)0.14%—Mar 10, 2023
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm