📦 Sdm845 Firmware

by Qualcomm

🔍 What is Sdm845 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33054

CRITICAL CVSS 9.1 Dec 5, 2023

CVE-2023-33054 is a cryptographic vulnerability in Qualcomm's GPS HLOS driver that allows improper authentication when downloading GNSS assistance data. This affects Android devices with Qualcomm chip...

CVE-2022-33288

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33288 is a critical buffer overflow vulnerability in Qualcomm's Core component that allows memory corruption when sending SCM commands to retrieve write protection information. Attackers can ...

CVE-2022-33231

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...

CVE-2020-11168

CRITICAL CVSS 9.8 Nov 12, 2020

This CVE describes a null-pointer dereference vulnerability in Qualcomm Snapdragon chipsets that allows attackers to access memory beyond allocated buffer boundaries. When exploited, it can lead to de...

CVE-2020-3703

CRITICAL CVSS 9.8 Nov 2, 2020

This CVE describes a buffer over-read vulnerability in Bluetooth peripheral firmware across multiple Qualcomm Snapdragon platforms. Attackers can exploit this by sending specially crafted Bluetooth pa...

CVE-2020-3667

CRITICAL CVSS 9.8 Sep 8, 2020

This is a critical buffer overflow vulnerability in Qualcomm's WPA MIC calculation that allows attackers to execute arbitrary code or cause denial of service. It affects numerous Snapdragon chipsets a...

CVE-2020-3669

CRITICAL CVSS 9.8 Sep 8, 2020

This CVE-2020-3669 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets' WLAN TCP/IP verification. It allows attackers to execute arbitrary code or cause denial of service by ex...

CVE-2023-33070

HIGH CVSS 7.1 Dec 5, 2023

CVE-2023-33070 is a vulnerability in Qualcomm Automotive OS where improper authentication to secure IO calls allows attackers to cause a transient denial-of-service condition. This affects automotive ...

CVE-2023-33017

HIGH CVSS 7.8 Dec 5, 2023

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices with vulnerable firmware, potentially allowing attac...

CVE-2023-28560

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in the WLAN Hardware Abstraction Layer (HAL) when processing devIndex values from untrusted WMI payloads. Attackers could potentially execute arbitrary code...

CVE-2023-28537

HIGH CVSS 8.4 Aug 8, 2023

This vulnerability allows memory corruption in Qualcomm's audio processing module (COmxApeDec) due to integer overflow during memory allocation. Attackers could potentially execute arbitrary code or c...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2022-33307

HIGH CVSS 8.4 Jun 6, 2023

CVE-2022-33307 is a double-free memory corruption vulnerability in Qualcomm automotive components that allows attackers to execute arbitrary code or cause denial of service. This affects automotive sy...

CVE-2022-40504

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows a denial-of-service (DoS) attack on mobile devices by sending a specially crafted Downlink Data Indication message to the modem. When exploited, it triggers a reachable asser...

CVE-2023-21666

HIGH CVSS 8.4 May 2, 2023

CVE-2023-21666 is a memory corruption vulnerability in Qualcomm's Adreno GPU driver (KGSL) that allows attackers to access sensitive data from graphics memory pools. This affects Android devices with ...

CVE-2022-40503

HIGH CVSS 8.2 Apr 13, 2023

This vulnerability allows attackers to read sensitive information from Bluetooth-enabled devices during A2DP audio streaming. It affects devices with Qualcomm Bluetooth chipsets that have not been pat...