qualcomm records
2,538 published records for vendor qualcomm.
Researcher profile
- Entered KEV
- 13 · 0.5%
- Weaponized
- 14 · 0.6%
- Pre-auth RCE
- 23
- With a fix record
- 0.2%
- Median publish → KEV
- 1 days
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')238
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer232
- CWE-416 Use After Free232
- CWE-126 Buffer Over-read205
- CWE-125 Out-of-bounds Read174
- CWE-20 Improper Input Validation161
The weakness classes this vendor ships most often: where to look.
CWEAll records
2,538 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2025-21479Weaponized | Incorrect Authorization in Graphicsqualcomm · aqt1000 firmware · CWE-863 | High8.6 | KEV | 0.8% | Jun 3, 2025 |
64This week | CVE-2025-21480Weaponized | Incorrect Authorization in Graphics Windowsqualcomm · aqt1000 firmware · CWE-863 | High8.6 | KEV | 0.5% | Jun 3, 2025 |
62This week | CVE-2013-2596Weaponized | Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Alinux · linux kernel · CWE-190 | High7.8 | KEV | 3.2% | Apr 12, 2013 |
61This week | CVE-2020-11261Weaponized | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, qualcomm · apq8009 firmware · CWE-787 | High7.8 | KEV | 1.6% | Jun 9, 2021 |
61This week | CVE-2021-1905Weaponized | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously.qualcomm · apq8009 firmware · CWE-416 | High7.8 | KEV | 1.5% | May 7, 2021 |
61This week | CVE-2026-21385Weaponized | Integer Overflow or Wraparound in Graphicsqualcomm · sm7675p firmware · CWE-190 | High7.8 | KEV | 1.3% | Mar 2, 2026 |
61This week | CVE-2023-33106Weaponized | Use of Out-of-range Pointer Offset in Graphicsqualcomm · ar8035 firmware · CWE-823 | High7.8 | KEV | 0.9% | Dec 4, 2023 |
61This week | CVE-2023-33107Weaponized | Integer Overflow or Wraparound in Graphics Linuxqualcomm · 315 5g iot modem firmware · CWE-190 | High7.8 | KEV | 0.9% | Dec 4, 2023 |
61This week | CVE-2023-33063Weaponized | Use After Free in DSP Servicesqualcomm · 315 5g iot modem firmware · CWE-416 | High7.8 | KEV | 0.7% | Dec 4, 2023 |
61This week | CVE-2024-43047Weaponized | Use After Free in DSP Servicequalcomm · fastconnect 6700 firmware · CWE-416 | High7.8 | KEV | 0.7% | Oct 7, 2024 |
61This week | CVE-2022-22071Weaponized | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Aqualcomm · apq8053 firmware · CWE-416 | High7.8 | KEV | 0.5% | Jun 14, 2022 |
60This week | CVE-2025-27038Weaponized | Use After Free in Graphicsqualcomm · ar8031 firmware · CWE-416 | High7.5 | KEV | 1.0% | Jun 3, 2025 |
52Plan | CVE-2021-1906Weaponized | Improper handling of address deregistration on failure can lead to new GPU address allocation failure.qualcomm · apq8009 firmware | Medium5.5 | KEV | 0.5% | May 7, 2021 |
50Plan | CVE-2005-4267Weaponized | Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends wiqualcomm · worldmail · CWE-119 | High7.5 | — | 66.8% | Dec 21, 2005 |
48Plan | CVE-2020-3657No exploit | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client thqualcomm · apq8009 firmware · CWE-120 | Critical9.8 | — | 28.3% | Nov 2, 2020 |
45Plan | CVE-2020-11117No exploit | u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulqualcomm · ipq4019 firmware · CWE-77 | Critical9.8 | — | 19.7% | Sep 8, 2020 |
43Plan | CVE-2020-11264No exploit | Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdqualcomm · apq8053 firmware · CWE-287 | Critical9.8 | — | 13.2% | Sep 8, 2021 |
43Plan | CVE-1999-0006Proof of concept | Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.qualcomm · qpopper · CWE-125 | Critical9.8 | — | 12.1% | Jul 14, 1998 |
43Plan | CVE-2003-0143Proof of concept | The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allowqualcomm · qpopper | Critical10.0 | — | 8.6% | Mar 18, 2003 |
41Plan | CVE-1999-0822Proof of concept | Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.qualcomm · qpopper | Critical10.0 | — | 4.9% | Nov 30, 1999 |
41Plan | CVE-2001-1046No exploit | Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.qualcomm · qpopper | Critical10.0 | — | 1.9% | Jun 2, 2001 |
40Plan | CVE-2021-30351No exploit | An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Autoqualcomm · apq8009 firmware · CWE-120 | Critical9.8 | — | 4.0% | Jan 3, 2022 |
40Plan | CVE-2021-1965Proof of concept | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragoqualcomm · aqt1000 firmware · CWE-20 | Critical9.8 | — | 3.0% | Jul 13, 2021 |
40Plan | CVE-2020-11153No exploit | u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution'qualcomm · apq8053 firmware · CWE-787 | Critical9.8 | — | 2.3% | Nov 2, 2020 |
40Plan | CVE-2017-14911No exploit | In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SDqualcomm · mdm9206 firmware · CWE-287 | Critical9.8 | — | 2.2% | Mar 30, 2018 |
- CVE-2025-2147964This week
Incorrect Authorization in Graphics
HighCVSS 8.6KEVWeaponizedEPSS 1%qualcomm · aqt1000 firmwareJun 3, 2025
- CVE-2025-2148064This week
Incorrect Authorization in Graphics Windows
HighCVSS 8.6KEVWeaponizedEPSS 0%qualcomm · aqt1000 firmwareJun 3, 2025
- CVE-2013-259662This week
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of A
HighCVSS 7.8KEVWeaponizedEPSS 3%linux · linux kernelApr 12, 2013
- CVE-2020-1126161This week
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,
HighCVSS 7.8KEVWeaponizedEPSS 2%qualcomm · apq8009 firmwareJun 9, 2021
- CVE-2021-190561This week
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously.
HighCVSS 7.8KEVWeaponizedEPSS 2%qualcomm · apq8009 firmwareMay 7, 2021
- CVE-2026-2138561This week
Integer Overflow or Wraparound in Graphics
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · sm7675p firmwareMar 2, 2026
- CVE-2023-3310661This week
Use of Out-of-range Pointer Offset in Graphics
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · ar8035 firmwareDec 4, 2023
- CVE-2023-3310761This week
Integer Overflow or Wraparound in Graphics Linux
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · 315 5g iot modem firmwareDec 4, 2023
- CVE-2023-3306361This week
Use After Free in DSP Services
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · 315 5g iot modem firmwareDec 4, 2023
- CVE-2024-4304761This week
Use After Free in DSP Service
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · fastconnect 6700 firmwareOct 7, 2024
- CVE-2022-2207161This week
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon A
HighCVSS 7.8KEVWeaponizedEPSS 0%qualcomm · apq8053 firmwareJun 14, 2022
- CVE-2025-2703860This week
Use After Free in Graphics
HighCVSS 7.5KEVWeaponizedEPSS 1%qualcomm · ar8031 firmwareJun 3, 2025
- CVE-2021-190652Plan
Improper handling of address deregistration on failure can lead to new GPU address allocation failure.
MediumCVSS 5.5KEVWeaponizedEPSS 1%qualcomm · apq8009 firmwareMay 7, 2021
- CVE-2005-426750Plan
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends wi
HighCVSS 7.5WeaponizedEPSS 67%qualcomm · worldmailDec 21, 2005
- CVE-2020-365748Plan
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client th
CriticalCVSS 9.8No exploitEPSS 28%qualcomm · apq8009 firmwareNov 2, 2020
- CVE-2020-1111745Plan
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resul
CriticalCVSS 9.8No exploitEPSS 20%qualcomm · ipq4019 firmwareSep 8, 2020
- CVE-2020-1126443Plan
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapd
CriticalCVSS 9.8No exploitEPSS 13%qualcomm · apq8053 firmwareSep 8, 2021
- CVE-1999-000643Plan
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
CriticalCVSS 9.8Proof of conceptEPSS 12%qualcomm · qpopperJul 14, 1998
- CVE-2003-014343Plan
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow
CriticalCVSS 10.0Proof of conceptEPSS 9%qualcomm · qpopperMar 18, 2003
- CVE-1999-082241Plan
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
CriticalCVSS 10.0Proof of conceptEPSS 5%qualcomm · qpopperNov 30, 1999
- CVE-2001-104641Plan
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
CriticalCVSS 10.0No exploitEPSS 2%qualcomm · qpopperJun 2, 2001
- CVE-2021-3035140Plan
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto
CriticalCVSS 9.8No exploitEPSS 4%qualcomm · apq8009 firmwareJan 3, 2022
- CVE-2021-196540Plan
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdrago
CriticalCVSS 9.8Proof of conceptEPSS 3%qualcomm · aqt1000 firmwareJul 13, 2021
- CVE-2020-1115340Plan
u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution'
CriticalCVSS 9.8No exploitEPSS 2%qualcomm · apq8053 firmwareNov 2, 2020
- CVE-2017-1491140Plan
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD
CriticalCVSS 9.8No exploitEPSS 2%qualcomm · mdm9206 firmwareMar 30, 2018