📦 Sm6375 Firmware

by Qualcomm

🔍 What is Sm6375 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33054

CRITICAL CVSS 9.1 Dec 5, 2023

CVE-2023-33054 is a cryptographic vulnerability in Qualcomm's GPS HLOS driver that allows improper authentication when downloading GNSS assistance data. This affects Android devices with Qualcomm chip...

CVE-2023-28540

CRITICAL CVSS 9.1 Oct 3, 2023

This vulnerability in Qualcomm Data Modem chips allows attackers to bypass TLS authentication during handshake, potentially enabling man-in-the-middle attacks. It affects devices using vulnerable Qual...

CVE-2022-33231

CRITICAL CVSS 9.3 Apr 13, 2023

CVE-2022-33231 is a double-free memory corruption vulnerability in Qualcomm chipsets that occurs during encryption key initialization. Successful exploitation could allow attackers to execute arbitrar...

CVE-2021-35104

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the FLAC audio header parser. Attackers can trigger this...

CVE-2021-35081

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via buffer overflow in Qualcomm Snapdragon chipsets. It affects devices using vulnerable Snapdragon comp...

CVE-2021-30347

CRITICAL CVSS 9.1 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper integrity checks leading to race conditions between PDCP and RRC tasks after receiving valid RRC command packets. Attackers could pot...

CVE-2021-30339

CRITICAL CVSS 9.0 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper cryptographic key generation due to insufficient buffer validation when reading PRNG output. Attackers could potentially generate wea...

CVE-2021-30341

CRITICAL CVSS 9.8 Jun 14, 2022

This vulnerability allows improper buffer size validation in DSM packets received by Qualcomm Snapdragon chipsets, leading to memory corruption. Attackers can exploit this to execute arbitrary code or...

CVE-2021-30343

CRITICAL CVSS 9.1 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows improper integrity checks leading to race conditions between PDCP and RRC tasks after receiving valid RRC Command packets. Attackers could pot...

CVE-2021-30317

CRITICAL CVSS 9.3 Feb 11, 2022

This vulnerability allows attackers to bypass image verification in Qualcomm Snapdragon chipsets by exploiting improper validation of ELF metadata in program headers. This affects numerous Snapdragon ...

CVE-2021-30285

CRITICAL CVSS 9.3 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon hypervisors allows improper memory region validation, potentially enabling attackers to map incorrect memory regions. It affects numerous Snapdragon platforms...

CVE-2021-30351

CRITICAL CVSS 9.8 Jan 3, 2022

CVE-2021-30351 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets, allowing attackers to execute arbitrary code or cause denial of service by exploiting improper validation du...

CVE-2021-30275

CRITICAL CVSS 9.3 Jan 3, 2022

This vulnerability is an integer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of service. It affects multiple Snapdragon product lines ...

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1975

CRITICAL CVSS 9.8 Nov 12, 2021

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses. Attackers can exploit this to execute arbitrary c...

CVE-2023-33079

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability allows memory corruption in the Audio subsystem when processing invalid audio recording data from the ADSP (Audio Digital Signal Processor). It affects Qualcomm devices with vulnera...

CVE-2023-33043

HIGH CVSS 7.5 Dec 5, 2023

This vulnerability allows a denial-of-service (DoS) attack on Qualcomm modems when a beam switch request is made with a non-configured bandwidth part (BWP). It affects devices using Qualcomm modems wi...

CVE-2023-33017

HIGH CVSS 7.8 Dec 5, 2023

This CVE describes a memory corruption vulnerability in the UEFI boot process when running a ListVars test during boot. It affects Qualcomm devices with vulnerable firmware, potentially allowing attac...

CVE-2023-33022

HIGH CVSS 8.4 Dec 5, 2023

This vulnerability allows memory corruption in the High-Level Operating System (HLOS) when user-space applications make specific IOCTL calls to Qualcomm hardware components. Attackers could exploit th...

CVE-2023-33034

HIGH CVSS 7.8 Oct 3, 2023

This vulnerability allows memory corruption while parsing ADSP response commands in Qualcomm chipsets, potentially enabling remote code execution. It affects devices using vulnerable Qualcomm componen...

CVE-2023-28560

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in the WLAN Hardware Abstraction Layer (HAL) when processing devIndex values from untrusted WMI payloads. Attackers could potentially execute arbitrary code...

CVE-2022-33275

HIGH CVSS 8.4 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm WLAN hardware abstraction layer due to improper array index validation. Attackers could potentially execute arbitrary code or cause denial of se...

CVE-2023-21656

HIGH CVSS 7.8 Jun 6, 2023

This vulnerability allows memory corruption in Qualcomm WLAN HOST drivers when processing WMI events from firmware. Attackers could potentially execute arbitrary code or cause denial of service. Affec...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2022-40523

HIGH CVSS 7.1 Jun 6, 2023

This vulnerability allows attackers to exploit indirect branch misprediction in Qualcomm chipsets to leak sensitive information from the kernel memory. It affects devices using vulnerable Qualcomm Sna...

CVE-2022-40529

HIGH CVSS 7.1 Jun 6, 2023

This vulnerability allows memory corruption in the Qualcomm kernel due to improper access control when processing mapping requests from root processes. It affects devices with Qualcomm chipsets, poten...

CVE-2022-40536

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted OTA (Over-The-Air) messages without proper authentication. It affects m...

CVE-2023-21628

HIGH CVSS 8.4 Jun 6, 2023

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing specific wireless commands. Attackers could potentially execute arbitrary code or cause ...

CVE-2022-33251

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending invalid network configuration data. The modem crashes due to a reachable assertion when p...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2022-40504

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows a denial-of-service (DoS) attack on mobile devices by sending a specially crafted Downlink Data Indication message to the modem. When exploited, it triggers a reachable asser...

CVE-2022-33305

HIGH CVSS 7.5 May 2, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted invalid messages on the DCCH channel. The NULL pointer dereference can ...

CVE-2022-40503

HIGH CVSS 8.2 Apr 13, 2023

This vulnerability allows attackers to read sensitive information from Bluetooth-enabled devices during A2DP audio streaming. It affects devices with Qualcomm Bluetooth chipsets that have not been pat...

CVE-2022-33270

HIGH CVSS 7.5 Apr 13, 2023

This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in Qualcomm modem firmware that allows a transient denial-of-service (DoS) attack when processing RRC Reconfiguration messages...

CVE-2021-35112

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows a user with standard permissions to access protected graphics memory regions due to improper access control in register configuration on Qualcomm Snapdragon chips. It affects...

CVE-2021-35123

HIGH CVSS 8.8 Jun 14, 2022

This is a buffer overflow vulnerability in Qualcomm's Snapdragon chipsets affecting GATT multi-notification functionality. Attackers can exploit this by sending specially crafted Bluetooth packets to ...

CVE-2021-35100

HIGH CVSS 7.5 Jun 14, 2022

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets when parsing ID3 tags in media files. It allows attackers to read memory beyond allocated buffers, potentially exposing sensiti...

CVE-2021-30350

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to insufficient validation of MBN header size against input buffer. Attackers could potentially execute arbitrary code o...

CVE-2021-30334

HIGH CVSS 8.4 Jun 14, 2022

This CVE describes a use-after-free vulnerability in Qualcomm Snapdragon chipsets where DRM file status isn't properly checked after file structure is freed. This could allow attackers to execute arbi...

CVE-2021-30281

HIGH CVSS 8.4 Jun 14, 2022

This vulnerability allows unauthorized access to secure memory space in Qualcomm Snapdragon chipsets due to improper access control checks during device configuration flashing. It affects multiple Sna...

CVE-2021-1950

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows authenticated users to bypass face authentication on affected Qualcomm Snapdragon devices due to improper secure memory cleaning between user sessions. It affects multiple Sn...

CVE-2021-30329

HIGH CVSS 7.5 Apr 1, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to trigger an assertion failure due to improper validation of TCI configuration. It affects automotive, compute, connectivity, indus...

CVE-2021-30332

HIGH CVSS 7.5 Apr 1, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to trigger a denial-of-service condition via improper validation of Over-The-Air (OTA) configuration data. It affects devices using ...

CVE-2021-35088

HIGH CVSS 8.2 Apr 1, 2022

This vulnerability allows attackers to read memory beyond intended boundaries during Wi-Fi SSID information element parsing when using DFS channels on affected Qualcomm Snapdragon chipsets. Successful...

CVE-2021-35103

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows an attacker to write data beyond allocated memory bounds in Qualcomm Snapdragon chipsets due to improper validation of timer values from firmware. It affects multiple Snapdra...

CVE-2021-35106

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows attackers to read memory beyond intended boundaries in Qualcomm Snapdragon chipsets due to improper WMI message length calculation. It affects numerous Snapdragon-powered dev...

CVE-2021-30322

HIGH CVSS 7.8 Feb 11, 2022

This vulnerability allows an attacker to write data beyond the intended memory boundaries in Qualcomm Snapdragon chipsets due to improper validation of GPIO configurations. It affects devices using Sn...

CVE-2021-30326

HIGH CVSS 7.5 Feb 11, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows remote attackers to cause denial of service through improper size validation of DownlinkPreemption IE in RRC messages. It affects Snapdragon A...

CVE-2021-35069

HIGH CVSS 7.8 Feb 11, 2022

This vulnerability allows improper validation of data length from DMA buffers, leading to memory corruption in Qualcomm Snapdragon chipsets. It affects multiple Snapdragon product lines including Auto...

CVE-2021-35075

HIGH CVSS 8.4 Feb 11, 2022

This vulnerability allows attackers to cause denial of service or potentially execute arbitrary code by exploiting a null pointer dereference in Qualcomm Snapdragon WDOG driver registration. It affect...

CVE-2021-30300

HIGH CVSS 7.5 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper hex data decoding in SIB2 OTA messages. When processing SRS configuration, the system assigns garbag...

CVE-2021-30307

HIGH CVSS 7.5 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper DNS response validation. When DNS clients request PTR, NAPTR, or SRV query types, malicious response...

CVE-2021-30311

HIGH CVSS 7.8 Jan 13, 2022

This vulnerability allows heap overflow attacks due to improper index validation in Qualcomm Snapdragon chipsets before allocating and writing to heap buffers. Attackers could potentially execute arbi...

CVE-2021-30319

HIGH CVSS 7.8 Jan 13, 2022

This vulnerability allows integer overflow in Qualcomm Snapdragon chipsets when processing WMI commands due to improper validation of command length parameters. Attackers could potentially execute arb...

CVE-2021-30353

HIGH CVSS 7.5 Jan 13, 2022

This vulnerability in Qualcomm Snapdragon chipsets involves improper validation of function pointer types, which can trigger an assertion failure. It affects various Snapdragon platforms including Aut...