📦 Sm7250 Firmware

by Qualcomm

🔍 What is Sm7250 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1975

CRITICAL CVSS 9.8 Nov 12, 2021

CVE-2021-1975 is a critical heap overflow vulnerability in Qualcomm Snapdragon chipsets that allows remote code execution via malformed DNS responses. Attackers can exploit this to execute arbitrary c...

CVE-2021-1976

CRITICAL CVSS 9.8 Sep 17, 2021

This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (peer-to-peer) device address validation. Attackers...

CVE-2021-1946

CRITICAL CVSS 9.8 Sep 9, 2021

A null pointer dereference vulnerability in Qualcomm Snapdragon chipsets allows remote attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted SDP (Se...

CVE-2021-1972

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P search functionality. Attackers can exploit improper va...

CVE-2020-11264

CRITICAL CVSS 9.1 Sep 8, 2021

This vulnerability allows attackers to inject arbitrary network packets during Wi-Fi authentication handshakes by exploiting improper authentication of non-EAPOL/WAPI frames. It affects Qualcomm Snapd...

CVE-2021-1916

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting a buffer underflow in Qualcomm Snapdragon chipsets. It affects numerous Qualcomm-powered devices ...

CVE-2021-1920

CRITICAL CVSS 9.8 Sep 8, 2021

CVE-2021-1920 is an integer underflow vulnerability in Qualcomm Snapdragon chipsets' RTCP packet handling that allows remote code execution. Attackers can send specially crafted RTCP packets to trigge...

CVE-2020-11168

CRITICAL CVSS 9.8 Nov 12, 2020

This CVE describes a null-pointer dereference vulnerability in Qualcomm Snapdragon chipsets that allows attackers to access memory beyond allocated buffer boundaries. When exploited, it can lead to de...

CVE-2020-11184

CRITICAL CVSS 9.8 Nov 12, 2020

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the video parser when processing specially crafted MP4 f...

CVE-2021-1981

HIGH CVSS 7.5 Nov 12, 2021

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets due to improper size checking of Bearer capability information elements in MT setup requests from networks. It affects multiple...

CVE-2021-30254

HIGH CVSS 7.8 Nov 12, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial of service through a buffer overflow in Qualcomm's factory calibration and test DIAG command. It affects numerous Snapdrag...

CVE-2021-30259

HIGH CVSS 7.8 Nov 12, 2021

This vulnerability allows out-of-bounds memory access due to improper validation of function table entries in Qualcomm Snapdragon chipsets. Attackers could potentially execute arbitrary code or cause ...

CVE-2021-30284

HIGH CVSS 7.5 Nov 12, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to potentially expose sensitive information or cause denial of service by exploiting improper handling of NAS messages when integrit...

CVE-2021-1983

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows buffer overflow attacks in Qualcomm Snapdragon VR service due to improper handling of negative data lengths in write requests. Attackers could potentially execute arbitrary c...

CVE-2021-1985

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability is a buffer over-read in Qualcomm's QVR Service configuration affecting multiple Snapdragon platforms. It allows attackers to read memory beyond allocated buffers, potentially expos...

CVE-2021-30257

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows attackers to read or write memory outside intended bounds in VR service due to insufficient validation of DSP selection values in Qualcomm Snapdragon chips. It affects device...

CVE-2021-30292

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows memory corruption due to improper validation of client data during memory allocation in Qualcomm Snapdragon chipsets. Attackers could potentially execute arbitrary code or ca...

CVE-2021-30310

HIGH CVSS 7.5 Oct 20, 2021

This vulnerability allows attackers to cause buffer overflow by sending specially crafted CF-ACK and CF-Poll data frames to affected Qualcomm Snapdragon chipsets. It affects a wide range of Snapdragon...

CVE-2021-30288

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows attackers to trigger a stack overflow by exploiting improper length validation of TLV (Type-Length-Value) data structures in Qualcomm Snapdragon chipsets. Successful exploita...

CVE-2021-1917

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows a null pointer dereference in the DIAG component of Qualcomm Snapdragon chipsets when memory allocation fails. It affects Snapdragon Auto, Compute, Connectivity, Industrial I...

CVE-2021-1936

HIGH CVSS 7.5 Oct 20, 2021

This vulnerability is a null pointer dereference in Qualcomm Snapdragon chipsets that can cause denial of service or potential code execution. It affects automotive, compute, connectivity, consumer Io...

CVE-2021-1959

HIGH CVSS 7.8 Oct 20, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows memory corruption due to improper input validation when handling index values. Attackers could exploit this to execute arbitrary code or cause...

CVE-2021-1977

HIGH CVSS 7.5 Oct 20, 2021

This vulnerability allows attackers to read beyond allocated memory boundaries during AEAD decryption in Qualcomm Snapdragon chipsets. It affects devices using Snapdragon Auto, Compute, Connectivity, ...

CVE-2021-30261

HIGH CVSS 8.4 Sep 17, 2021

This vulnerability allows attackers to trigger integer and heap overflows by sending specially crafted beacon template update commands to affected Qualcomm Snapdragon chipsets. Successful exploitation...

CVE-2021-1947

HIGH CVSS 8.4 Sep 17, 2021

This CVE describes a use-after-free vulnerability in Qualcomm's kernel graphics driver affecting multiple Snapdragon platforms. Attackers could exploit this to execute arbitrary code in kernel context...

CVE-2021-30295

HIGH CVSS 8.4 Sep 9, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial of service via heap overflow in Qualcomm Snapdragon chipsets. It affects multiple Qualcomm Snapdragon platforms including ...

CVE-2021-1952

HIGH CVSS 7.8 Sep 9, 2021

A buffer over-read vulnerability in Qualcomm Snapdragon chipsets allows attackers to read memory beyond allocated buffers due to insufficient length validation. This affects devices using vulnerable S...

CVE-2021-1935

HIGH CVSS 7.1 Sep 9, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows potential denial of service or arbitrary code execution due to a null pointer dereference during key import operations. It affects multiple Sn...

CVE-2021-1909

HIGH CVSS 7.3 Sep 9, 2021

CVE-2021-1909 is a buffer overflow vulnerability in Qualcomm Snapdragon trusted applications due to insufficient parameter length validation. This allows attackers to execute arbitrary code in trusted...

CVE-2021-1914

HIGH CVSS 7.5 Sep 8, 2021

CVE-2021-1914 is an infinite loop vulnerability in Qualcomm Snapdragon chipsets where improper handling of unsupported input can cause a denial of service condition. This affects various Snapdragon pl...