Qualcomm
Qualcomm SD 625 Firmware: vulnerabilities and CVEs
Qualcomm SD 625 Firmware has 434 published vulnerabilities, 0 of them in the last 12 months. 200 are rated critical and 0 are listed by CISA as actively exploited.
CVEs434
Last 12 months0
Critical200
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5852 | High (7.8) | 0.12% | — | Nov 26, 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2017-18307 | Medium (5.5) | 0.11% | — | Nov 26, 2024 | Information disclosure possible while audio playback. |
| CVE-2017-18306 | Medium (5.5) | 0.11% | — | Nov 26, 2024 | Information disclosure due to uninitialized variable. |
| CVE-2018-11952 | High (7.8) | 0.11% | — | Nov 26, 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2018-11922 | Medium (5.5) | 0.23% | — | Nov 26, 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-17772 | Critical (9.8) | 0.35% | — | Nov 26, 2024 | In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation. |
| CVE-2017-11076 | Critical (9.8) | 0.35% | — | Nov 26, 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2017-9711 | High (7.8) | 0.12% | — | Nov 22, 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2019-10530 | High (7.8) | 0.19% | — | Dec 12, 2019 | Lack of check of data truncation on user supplied data in kernel leads to buffer overflow in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… |
| CVE-2019-2332 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-2331 | Critical (9.8) | 1.2% | — | Nov 6, 2019 | Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2325 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2324 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-2323 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-2285 | Critical (9.8) | 1.1% | — | Nov 6, 2019 | Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-2283 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-2275 | Medium (5.5) | 0.19% | — | Nov 6, 2019 | While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key operations are invoked(Depends on CVE-2018-13907) in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-2258 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2019-2249 | Critical (9.8) | 1.4% | — | Nov 6, 2019 | Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-2246 | High (7.8) | 0.20% | — | Nov 6, 2019 | Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-10542 | Critical (9.8) | 0.71% | — | Nov 6, 2019 | Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon… |
| CVE-2019-10541 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-10534 | Critical (9.8) | 1.1% | — | Nov 6, 2019 | Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-10533 | Critical (9.8) | 0.91% | — | Nov 6, 2019 | Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-10531 | Critical (9.8) | 0.90% | — | Nov 6, 2019 | Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205,… |
| CVE-2019-10529 | High (8.1) | 1.7% | — | Nov 6, 2019 | Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2019-10528 | Critical (9.8) | 0.71% | — | Nov 6, 2019 | Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-10524 | High (7.8) | 0.19% | — | Nov 6, 2019 | Lack of check for a negative value returned for get_clk is wrongly interpreted as valid pointer and lead to use after free in clk driver in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-10522 | Critical (9.8) | 0.71% | — | Nov 6, 2019 | While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-10515 | Medium (5.5) | 0.17% | — | Nov 6, 2019 | DCI client which might be preemptively freed up might be accessed for transferring packets leading to kernel error in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.