« Back to list

Qualcomm

Qualcomm Sdm660 Firmware: vulnerabilities and CVEs

Qualcomm Sdm660 Firmware has 466 published vulnerabilities, 0 of them in the last 12 months. 153 are rated critical and 1 are listed by CISA as actively exploited.

CVEs466
Last 12 months0
Critical153
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33063High (7.8)0.69%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2017-11076Critical (9.8)0.35%—Nov 26, 2024
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
CVE-2023-33080High (7.5)0.34%—Dec 5, 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33070Medium (5.5)0.14%—Dec 5, 2023
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
CVE-2023-33063High (7.8)0.69%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33054Critical (9.1)0.36%—Dec 5, 2023
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
CVE-2023-33018High (7.8)0.11%—Dec 5, 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33059High (7.8)0.11%—Nov 7, 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33031High (7.8)0.11%—Nov 7, 2023
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
CVE-2022-33275High (7.8)0.12%—Sep 5, 2023
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-21670High (7.8)0.12%—Jun 6, 2023
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
CVE-2023-21661High (7.5)0.38%—Jun 6, 2023
Transient DOS while parsing WLAN beacon or probe-response frame.
CVE-2023-21659High (7.5)0.38%—Jun 6, 2023
Transient DOS in WLAN Firmware while processing frames with missing header fields.
CVE-2023-21657High (7.8)0.12%—Jun 6, 2023
Memoru corruption in Audio when ADSP sends input during record use case.
CVE-2023-21628High (7.8)0.12%—Jun 6, 2023
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2022-40521High (7.5)0.35%—Jun 6, 2023
Transient DOS due to improper authorization in Modem
CVE-2022-40507High (7.8)1.3%—Jun 6, 2023
Memory corruption due to double free in Core while mapping HLOS address to the list.
CVE-2022-33264High (7.8)0.11%—Jun 6, 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-22076Medium (5.5)0.11%—Jun 6, 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40504High (7.5)0.38%—May 2, 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
CVE-2023-21666High (7.8)0.18%—May 2, 2023
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665High (7.8)0.18%—May 2, 2023
Memory corruption in Graphics while importing a file.
CVE-2022-40532High (7.8)0.12%—Apr 13, 2023
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
CVE-2022-40503High (7.5)0.41%—Apr 13, 2023
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
CVE-2022-33302High (7.8)0.12%—Apr 13, 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33289Medium (6.8)0.19%—Apr 13, 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
CVE-2022-33231High (7.8)0.08%—Apr 13, 2023
Memory corruption due to double free in core while initializing the encryption key.
CVE-2021-30327Medium (6.8)0.20%—Jun 14, 2022
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon…
CVE-2020-3639Critical (9.8)0.91%—Nov 12, 2020
u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon…
CVE-2020-11207High (7.8)1.5%—Nov 12, 2020
Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052,…
CVE-2020-11206High (7.8)1.8%—Nov 12, 2020
Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1
  3. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm