📦 Sd7c Firmware

by Qualcomm

🔍 What is Sd7c Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-40510

CRITICAL CVSS 9.8 Aug 8, 2023

CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause denial of service. The vulnerability affects devices ...

CVE-2022-33231

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...

CVE-2022-40514

CRITICAL CVSS 9.8 Feb 12, 2023

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in WLAN firmware. It affects Qualcomm chipsets used ...

CVE-2021-30341

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows improper buffer size validation in DSM packets received by Qualcomm Snapdragon chipsets, leading to memory corruption. Attackers can exploit this to execute arbitrary code or...

CVE-2021-30317

CRITICAL CVSS 9.3 Feb 11, 2022

This vulnerability allows attackers to bypass image verification in Qualcomm Snapdragon chipsets by exploiting improper validation of ELF metadata in program headers. This affects numerous Snapdragon ...

CVE-2021-30285

CRITICAL CVSS 9.3 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon hypervisors allows improper memory region validation, potentially enabling attackers to map incorrect memory regions. It affects numerous Snapdragon platforms...

CVE-2021-30275

CRITICAL CVSS 9.3 Jan 3, 2022

This vulnerability is an integer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of service. It affects multiple Snapdragon product lines ...

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1975

CRITICAL CVSS 9.8 Nov 12, 2021

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses. Attackers can exploit this to execute arbitrary c...

CVE-2020-11182

CRITICAL CVSS 9.8 Jun 9, 2021

This vulnerability allows remote code execution via heap overflow in Qualcomm Snapdragon chipsets when parsing NAL headers in video processing. It affects devices using vulnerable Snapdragon Auto, Com...

CVE-2020-11159

CRITICAL CVSS 9.1 Jun 9, 2021

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing WPA/RSN information elements in Wi-Fi beacon and response frames. Attackers can exploit this to read...

CVE-2020-11126

CRITICAL CVSS 9.1 Jun 9, 2021

This vulnerability allows attackers to read memory beyond intended boundaries while parsing WLAN frames in Qualcomm Snapdragon chipsets. It affects numerous Snapdragon product lines including Auto, Mo...

CVE-2020-11276

CRITICAL CVSS 9.1 Feb 22, 2021

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets that occurs when processing Wi-Fi P2P (Peer-to-Peer) information elements and NOA (Notice of Absence) attributes in beacon and ...

CVE-2023-28538

HIGH CVSS 8.4 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm WIN Product's UEFI region when invoking the WinAcpi update driver. Attackers could exploit this to execute arbitrary code or cause system crashe...

CVE-2023-21626

HIGH CVSS 7.1 Aug 8, 2023

This cryptographic vulnerability in Qualcomm's HLOS (High-Level Operating System) allows improper authentication during key velocity checks when multiple keys are involved. It affects devices using Qu...

CVE-2022-33248

HIGH CVSS 7.8 Feb 12, 2023

This vulnerability allows memory corruption in Qualcomm's User Identity Module due to an integer overflow that leads to buffer overflow when processing segments via QMI HTTP. It affects devices using ...

CVE-2022-33277

HIGH CVSS 8.4 Feb 12, 2023

This CVE describes a buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when processing WMI commands. Attackers could potentially execute arbitrary code on affected...

CVE-2021-35083

HIGH CVSS 8.2 Jun 14, 2022

This vulnerability allows attackers to read memory beyond intended boundaries due to improper certificate chain validation in Qualcomm Snapdragon chipsets. It affects devices using vulnerable Snapdrag...

CVE-2021-30350

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to insufficient validation of MBN header size against input buffer. Attackers could potentially execute arbitrary code o...

CVE-2021-30281

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows unauthorized access to secure memory space in Qualcomm Snapdragon chipsets due to improper access control checks during device configuration flashing. It affects multiple Sna...

CVE-2021-30322

HIGH CVSS 7.8 Feb 11, 2022

This vulnerability allows an attacker to write data beyond the intended memory boundaries in Qualcomm Snapdragon chipsets due to improper validation of GPIO configurations. It affects devices using Sn...

CVE-2021-30300

HIGH CVSS 7.5 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper hex data decoding in SIB2 OTA messages. When processing SRS configuration, the system assigns garbag...

CVE-2021-30307

HIGH CVSS 7.5 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper DNS response validation. When DNS clients request PTR, NAPTR, or SRV query types, malicious response...

CVE-2021-30274

HIGH CVSS 8.4 Jan 3, 2022

This integer overflow vulnerability in Qualcomm Snapdragon chipsets allows attackers to potentially bypass access control mechanisms or execute arbitrary code. It affects multiple Snapdragon product l...

CVE-2021-30272

HIGH CVSS 7.3 Jan 3, 2022

A null pointer dereference vulnerability in Qualcomm Snapdragon thread cache operation handler allows attackers to cause denial of service or potentially execute arbitrary code by exploiting insuffici...

CVE-2021-30278

HIGH CVSS 7.1 Jan 3, 2022

This vulnerability in Qualcomm's TrustZone memory transfer interface allows improper input validation that could lead to information disclosure. It affects multiple Snapdragon platforms including Auto...

CVE-2021-30282

HIGH CVSS 8.4 Jan 3, 2022

This vulnerability allows attackers to write data outside the intended memory boundaries in Qualcomm Snapdragon chipsets due to improper validation of partition counts in RAM partition tables. It affe...

CVE-2021-30289

HIGH CVSS 7.8 Jan 3, 2022

This vulnerability allows attackers to execute arbitrary code or cause denial of service via buffer overflow in Qualcomm Snapdragon chipsets. It affects devices using Snapdragon Auto, Compute, Consume...

CVE-2021-30303

HIGH CVSS 7.8 Jan 3, 2022

This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Qualcomm Snapdragon devices by sending specially crafted segmented WMI commands that trigger a buff...

CVE-2020-11263

HIGH CVSS 7.3 Jan 3, 2022

CVE-2020-11263 is an integer overflow vulnerability in Qualcomm Snapdragon chipsets that occurs when improper checks are performed after memory address and size alignment. This allows attackers to pot...

CVE-2021-30268

HIGH CVSS 7.8 Jan 3, 2022

This vulnerability allows heap memory corruption due to insufficient input validation when processing HWTC IQ Capture commands in Qualcomm Snapdragon chipsets. Attackers could potentially execute arbi...

CVE-2021-30270

HIGH CVSS 7.3 Jan 3, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows potential denial-of-service or arbitrary code execution due to a null pointer dereference in the thread profile trap handler. Attackers could ...

CVE-2021-30259

HIGH CVSS 7.8 Nov 12, 2021

This vulnerability allows out-of-bounds memory access due to improper validation of function table entries in Qualcomm Snapdragon chipsets. Attackers could potentially execute arbitrary code or cause ...

CVE-2021-30288

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows attackers to trigger a stack overflow by exploiting improper length validation of TLV (Type-Length-Value) data structures in Qualcomm Snapdragon chipsets. Successful exploita...

CVE-2021-1959

HIGH CVSS 7.8 Oct 20, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to improper input validation when handling index values. Attackers could exploit this to execute arbitrary code or cause...

CVE-2021-1952

HIGH CVSS 7.8 Sep 9, 2021

A buffer over-read vulnerability in Qualcomm Snapdragon chipsets allows attackers to read memory beyond allocated buffers due to insufficient length validation. This affects devices using vulnerable S...

CVE-2021-1935

HIGH CVSS 7.1 Sep 9, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows potential denial of service or arbitrary code execution due to a null pointer dereference during key import operations. It affects multiple Sn...

CVE-2021-1909

HIGH CVSS 7.3 Sep 9, 2021

CVE-2021-1909 is a buffer overflow vulnerability in Qualcomm Snapdragon trusted applications due to insufficient parameter length validation. This allows attackers to execute arbitrary code in trusted...

CVE-2021-1953

HIGH CVSS 7.5 Jul 13, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows remote attackers to trigger a reachable assertion by sending malformed Fine Timing Measurement Request (FTMR) frames. Exploitation could lead ...

CVE-2021-1938

HIGH CVSS 7.5 Jul 13, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows assertion failures due to improper verification during peer creation/deletion operations. It affects multiple Snapdragon product lines includi...

CVE-2021-1889

HIGH CVSS 8.4 Jul 13, 2021

This vulnerability allows a buffer overflow in Qualcomm Snapdragon Trusted Applications due to missing length validation. Attackers could potentially execute arbitrary code with elevated privileges. A...

CVE-2020-11306

HIGH CVSS 7.8 Jun 9, 2021

This CVE describes an integer overflow vulnerability in the RPMB (Replay Protected Memory Block) counter in Qualcomm Snapdragon chipsets. Attackers could exploit this by providing specially crafted da...

CVE-2020-11298

HIGH CVSS 7.8 Jun 9, 2021

This vulnerability allows non-secure clients to modify permissions on shared memory buffers while the system is waiting for callback responses in Qualcomm Snapdragon chipsets. This could enable privil...

CVE-2020-11178

HIGH CVSS 7.8 Jun 9, 2021

This vulnerability allows trusted applications in Qualcomm's TrustZone to overwrite protected memory regions of other applications. It affects multiple Qualcomm Snapdragon platforms across automotive,...

CVE-2020-11235

HIGH CVSS 7.8 Jun 9, 2021

CVE-2020-11235 is a buffer overflow vulnerability in Qualcomm Snapdragon chipsets that occurs when parsing unified commands without proper input validation. Attackers could exploit this to execute arb...

CVE-2020-11241

HIGH CVSS 7.5 Jun 9, 2021

This vulnerability allows an attacker to trigger an out-of-bounds read in Qualcomm Snapdragon chipsets when processing EAPOL keys with insufficient length in NAN shared key descriptor attributes. This...

CVE-2021-1925

HIGH CVSS 7.5 May 7, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks through improper handling of group management action frames in wireless communication. Attackers can send specially ...

CVE-2020-11288

HIGH CVSS 7.8 May 7, 2021

CVE-2020-11288 is an out-of-bounds write vulnerability in Qualcomm's PlayReady DRM implementation affecting multiple Snapdragon platforms. This allows attackers to execute arbitrary code or cause deni...