« Back to list

Qualcomm

Qualcomm Sd888 5G Firmware: vulnerabilities and CVEs

Qualcomm Sd888 5G Firmware has 336 published vulnerabilities, 0 of them in the last 12 months. 49 are rated critical and 2 are listed by CISA as actively exploited.

CVEs336
Last 12 months0
Critical49
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-22071High (7.8)0.46%⚠ Active exploitationJun 14, 2022
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2020-11261High (7.8)1.6%⚠ Active exploitationJun 9, 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-30299Medium (6.7)0.12%—Nov 22, 2024
Possible out of bound access in audio module due to lack of validation of user provided input.
CVE-2023-21664High (7.8)0.12%—Sep 5, 2023
Memory Corruption in Core Platform while printing the response buffer in log.
CVE-2023-21663High (7.8)0.11%—Sep 5, 2023
Memory Corruption while accessing metadata in Display.
CVE-2023-21662High (7.8)0.12%—Sep 5, 2023
Memory corruption in Core Platform while printing the response buffer in log.
CVE-2023-21655High (7.8)0.11%—Sep 5, 2023
Memory corruption in Audio while validating and mapping metadata.
CVE-2023-21646High (7.5)0.38%—Sep 5, 2023
Transient DOS in Modem while processing invalid System Information Block 1.
CVE-2022-33220Medium (5.5)0.11%—Sep 5, 2023
Information disclosure in Automotive multimedia due to buffer over-read.
CVE-2023-22666High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21652High (7.1)0.10%—Aug 8, 2023
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
CVE-2023-21651High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
CVE-2023-21627High (7.8)0.12%—Aug 8, 2023
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
CVE-2023-21626High (7.1)0.11%—Aug 8, 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Critical (9.8)0.43%—Aug 8, 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-40540High (7.8)0.17%—Mar 10, 2023
Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel.
CVE-2022-40537Critical (9.8)0.36%—Mar 10, 2023
Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
CVE-2022-40531High (7.8)0.12%—Mar 10, 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
CVE-2022-40530High (7.8)0.13%—Mar 10, 2023
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
CVE-2022-40527High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
CVE-2022-40515Critical (9.8)0.33%—Mar 10, 2023
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
CVE-2022-33278High (7.8)0.12%—Mar 10, 2023
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
CVE-2022-33272High (7.5)0.41%—Mar 10, 2023
Transient DOS in modem due to reachable assertion.
CVE-2022-33260High (7.8)0.12%—Mar 10, 2023
Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.
CVE-2022-33257High (7)0.09%—Mar 10, 2023
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
CVE-2022-33256Critical (9.8)0.53%—Mar 10, 2023
Memory corruption due to improper validation of array index in Multi-mode call processor.
CVE-2022-33254High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
CVE-2022-33250High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
CVE-2022-33244High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
CVE-2022-33242High (7.8)0.14%—Mar 10, 2023
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
CVE-2022-33213High (8.8)0.41%—Mar 10, 2023
Memory corruption in modem due to buffer overflow while processing a PPP packet
CVE-2022-25705High (7.8)0.13%—Mar 10, 2023
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1068 Exploitation for Privilege Escalation2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm