Qualcomm
Qualcomm Snapdragon 750g 5G Mobile Firmware: vulnerabilities and CVEs
Qualcomm Snapdragon 750g 5G Mobile Firmware has 24 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs24
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27061 | High (7.8) | 0.09% | — | Jul 8, 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| CVE-2025-27042 | High (7.8) | 0.09% | — | Jul 8, 2025 | Memory corruption while processing video packets received from video firmware. |
| CVE-2025-21454 | High (7.5) | 0.22% | — | Jul 8, 2025 | Transient DOS while processing received beacon frame. |
| CVE-2025-21449 | High (7.5) | 0.22% | — | Jul 8, 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. |
| CVE-2025-21433 | Medium (5.5) | 0.08% | — | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| CVE-2025-21432 | High (7.8) | 0.09% | — | Jul 8, 2025 | Memory corruption while retrieving the CBOR data from TA. |
| CVE-2025-21467 | High (7.8) | 0.11% | — | May 6, 2025 | Memory corruption while reading the FW response from the shared queue. |
| CVE-2025-21453 | High (7.8) | 0.11% | — | May 6, 2025 | Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. |
| CVE-2024-49835 | High (7.8) | 0.11% | — | May 6, 2025 | Memory corruption while reading secure file. |
| CVE-2024-33060 | High (7.8) | 0.17% | — | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. |
| CVE-2023-43551 | High (7.5) | 0.26% | — | Jun 3, 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| CVE-2024-21475 | High (7.8) | 0.11% | — | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| CVE-2023-43529 | High (7.5) | 0.32% | — | May 6, 2024 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| CVE-2024-21468 | High (7.8) | 0.11% | — | Apr 1, 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-33101 | High (7.5) | 0.32% | — | Apr 1, 2024 | Transient DOS while processing DL NAS TRANSPORT message with payload length 0. |
| CVE-2023-33099 | High (7.5) | 0.32% | — | Apr 1, 2024 | Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. |
| CVE-2023-33023 | High (7.8) | 0.11% | — | Apr 1, 2024 | Memory corruption while processing finish_sign command to pass a rsp buffer. |
| CVE-2023-28547 | High (7.8) | 0.11% | — | Apr 1, 2024 | Memory corruption in SPS Application while requesting for public key in sorter TA. |
| CVE-2023-33104 | High (7.5) | 0.32% | — | Mar 4, 2024 | Transient DOS while processing PDU Release command with a parameter PDU ID out of range. |
| CVE-2023-33096 | High (7.5) | 0.32% | — | Mar 4, 2024 | Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. |
| CVE-2023-33095 | High (7.5) | 0.32% | — | Mar 4, 2024 | Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. |
| CVE-2023-33086 | High (7.5) | 0.32% | — | Mar 4, 2024 | Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |
| CVE-2023-33066 | High (7.8) | 0.11% | — | Mar 4, 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-28578 | High (7.8) | 0.12% | — | Mar 4, 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.