Qualcomm
Qualcomm Sdm660 Firmware: vulnerabilities and CVEs
Qualcomm Sdm660 Firmware has 466 published vulnerabilities, 0 of them in the last 12 months. 153 are rated critical and 1 are listed by CISA as actively exploited.
CVEs466
Last 12 months0
Critical153
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33063 | High (7.8) | 0.69% | ⚠ Active exploitation | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11076 | Critical (9.8) | 0.35% | — | Nov 26, 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2023-33080 | High (7.5) | 0.34% | — | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33070 | Medium (5.5) | 0.14% | — | Dec 5, 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. |
| CVE-2023-33063 | High (7.8) | 0.69% | ⚠ Active exploitation | Dec 5, 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33054 | Critical (9.1) | 0.36% | — | Dec 5, 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| CVE-2023-33018 | High (7.8) | 0.11% | — | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-33059 | High (7.8) | 0.11% | — | Nov 7, 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-33031 | High (7.8) | 0.11% | — | Nov 7, 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. |
| CVE-2022-33275 | High (7.8) | 0.12% | — | Sep 5, 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. |
| CVE-2023-21670 | High (7.8) | 0.12% | — | Jun 6, 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. |
| CVE-2023-21661 | High (7.5) | 0.38% | — | Jun 6, 2023 | Transient DOS while parsing WLAN beacon or probe-response frame. |
| CVE-2023-21659 | High (7.5) | 0.38% | — | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. |
| CVE-2023-21657 | High (7.8) | 0.12% | — | Jun 6, 2023 | Memoru corruption in Audio when ADSP sends input during record use case. |
| CVE-2023-21628 | High (7.8) | 0.12% | — | Jun 6, 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-40521 | High (7.5) | 0.35% | — | Jun 6, 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-40507 | High (7.8) | 1.3% | — | Jun 6, 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. |
| CVE-2022-33264 | High (7.8) | 0.11% | — | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-22076 | Medium (5.5) | 0.11% | — | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-40504 | High (7.5) | 0.38% | — | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2023-21666 | High (7.8) | 0.18% | — | May 2, 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | High (7.8) | 0.18% | — | May 2, 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-40503 | High (7.5) | 0.41% | — | Apr 13, 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
| CVE-2022-33302 | High (7.8) | 0.12% | — | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33289 | Medium (6.8) | 0.19% | — | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-33231 | High (7.8) | 0.08% | — | Apr 13, 2023 | Memory corruption due to double free in core while initializing the encryption key. |
| CVE-2021-30327 | Medium (6.8) | 0.20% | — | Jun 14, 2022 | Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon… |
| CVE-2020-3639 | Critical (9.8) | 0.91% | — | Nov 12, 2020 | u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2020-11207 | High (7.8) | 1.5% | — | Nov 12, 2020 | Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052,… |
| CVE-2020-11206 | High (7.8) | 1.8% | — | Nov 12, 2020 | Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.