📦 Sm4375 Firmware

by Qualcomm

🔍 What is Sm4375 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33054

CRITICAL CVSS 9.1 Dec 5, 2023

CVE-2023-33054 is a cryptographic vulnerability in Qualcomm's GPS HLOS driver that allows improper authentication when downloading GNSS assistance data. This affects Android devices with Qualcomm chip...

CVE-2023-28540

CRITICAL CVSS 9.1 Oct 3, 2023

This vulnerability in Qualcomm Data Modem chips allows attackers to bypass TLS authentication during handshake, potentially enabling man-in-the-middle attacks. It affects devices using vulnerable Qual...

CVE-2023-21651

CRITICAL CVSS 9.3 Aug 8, 2023

CVE-2023-21651 is a memory corruption vulnerability in Qualcomm's Trusted Execution Environment (TEE) due to incorrect type conversion in secure_io_read/write functions. This allows attackers to poten...

CVE-2022-40510

CRITICAL CVSS 9.8 Aug 8, 2023

CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause denial of service. The vulnerability affects devices ...

CVE-2022-33231

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...

CVE-2023-33079

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability allows memory corruption in the Audio subsystem when processing invalid audio recording data from the ADSP (Audio Digital Signal Processor). It affects Qualcomm devices with vulnera...

CVE-2023-33043

HIGH CVSS 7.5 Dec 5, 2023

This vulnerability allows a denial-of-service (DoS) attack on Qualcomm modems when a beam switch request is made with a non-configured bandwidth part (BWP). It affects devices using Qualcomm modems wi...

CVE-2023-33017

HIGH CVSS 7.8 Dec 5, 2023

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices with vulnerable firmware, potentially allowing attac...

CVE-2023-33022

HIGH CVSS 8.4 Dec 5, 2023

This vulnerability allows memory corruption in the High-Level Operating System (HLOS) when user-space applications make specific IOCTL calls to Qualcomm hardware components. Attackers could exploit th...

CVE-2023-33034

HIGH CVSS 7.8 Oct 3, 2023

This vulnerability allows memory corruption while parsing ADSP response commands in Qualcomm chipsets, potentially enabling remote code execution. It affects devices using vulnerable Qualcomm componen...

CVE-2023-28560

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in the WLAN Hardware Abstraction Layer (HAL) when processing devIndex values from untrusted WMI payloads. Attackers could potentially execute arbitrary code...

CVE-2023-21646

HIGH CVSS 7.5 Sep 5, 2023

This vulnerability allows attackers to cause a denial-of-service condition in Qualcomm modems by sending specially crafted System Information Block 1 messages. The modem may crash or become unresponsi...

CVE-2022-33275

HIGH CVSS 8.4 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm WLAN hardware abstraction layer due to improper array index validation. Attackers could potentially execute arbitrary code or cause denial of se...

CVE-2023-28537

HIGH CVSS 8.4 Aug 8, 2023

This vulnerability allows memory corruption in Qualcomm's audio processing module (COmxApeDec) due to integer overflow during memory allocation. Attackers could potentially execute arbitrary code or c...

CVE-2023-21626

HIGH CVSS 7.1 Aug 8, 2023

This cryptographic vulnerability in Qualcomm's HLOS (High-Level Operating System) allows improper authentication during key velocity checks when multiple keys are involved. It affects devices using Qu...

CVE-2023-22666

HIGH CVSS 8.4 Aug 8, 2023

CVE-2023-22666 is a memory corruption vulnerability in Qualcomm's audio processing component when playing specially crafted AMR-WB+ audio clips. This vulnerability allows attackers to execute arbitrar...

CVE-2023-21656

HIGH CVSS 7.8 Jun 6, 2023

This vulnerability allows memory corruption in Qualcomm WLAN HOST drivers when processing WMI events from firmware. Attackers could potentially execute arbitrary code or cause denial of service. Affec...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2022-40523

HIGH CVSS 7.1 Jun 6, 2023

This vulnerability allows attackers to exploit indirect branch misprediction in Qualcomm chipsets to leak sensitive information from the kernel memory. It affects devices using vulnerable Qualcomm Sna...

CVE-2022-40529

HIGH CVSS 7.1 Jun 6, 2023

This vulnerability allows memory corruption in the Qualcomm kernel due to improper access control when processing mapping requests from root processes. It affects devices with Qualcomm chipsets, poten...

CVE-2022-40536

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted OTA (Over-The-Air) messages without proper authentication. It affects m...

CVE-2023-21628

HIGH CVSS 8.4 Jun 6, 2023

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing specific wireless commands. Attackers could potentially execute arbitrary code or cause ...

CVE-2022-33251

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending invalid network configuration data. The modem crashes due to a reachable assertion when p...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2022-40504

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows a denial-of-service (DoS) attack on mobile devices by sending a specially crafted Downlink Data Indication message to the modem. When exploited, it triggers a reachable asser...

CVE-2022-33305

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted invalid messages on the DCCH channel. The NULL pointer dereference can ...

CVE-2022-40503

HIGH CVSS 8.2 Apr 13, 2023

This vulnerability allows attackers to read sensitive information from Bluetooth-enabled devices during A2DP audio streaming. It affects devices with Qualcomm Bluetooth chipsets that have not been pat...

CVE-2022-33270

HIGH CVSS 7.5 Apr 13, 2023

This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in Qualcomm modem firmware that allows a transient denial-of-service (DoS) attack when processing RRC Reconfiguration messages...