📦 Sm7635p Firmware

by Qualcomm

🔍 What is Sm7635p Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-21450

CRITICAL CVSS 9.1 Jul 8, 2025

This vulnerability allows attackers to intercept or manipulate data during downloads due to insecure connection methods. It affects systems using Qualcomm components with vulnerable firmware versions....

CVE-2026-21385

HIGH CVSS 7.8 Mar 2, 2026

This CVE describes a memory corruption vulnerability in alignment-based memory allocation functions. Attackers can exploit this to execute arbitrary code or cause denial of service. The vulnerability ...

CVE-2025-59600

HIGH CVSS 7.8 Mar 2, 2026

This CVE describes a buffer overflow vulnerability in Qualcomm software where user-supplied data is added without proper bounds checking, leading to memory corruption. Attackers could exploit this to ...

CVE-2025-47376

HIGH CVSS 7.8 Mar 2, 2026

This vulnerability allows memory corruption when multiple processes concurrently access a shared buffer during IOCTL calls in Qualcomm components. Attackers could potentially execute arbitrary code or...

CVE-2025-47373

HIGH CVSS 7.8 Mar 2, 2026

This CVE describes a memory corruption vulnerability in Qualcomm Trusted Application (TA) invocation where accessing buffers with invalid length can lead to arbitrary code execution. It affects device...

CVE-2025-47366

HIGH CVSS 7.1 Feb 2, 2026

A cryptographic vulnerability in Qualcomm's Trusted Zone when triggered by the High-Level Operating System (HLOS) providing incorrect input. This allows potential cryptographic bypass or manipulation ...

CVE-2025-47398

HIGH CVSS 7.8 Feb 2, 2026

This CVE describes a use-after-free vulnerability in Qualcomm GPU memory management where improper pointer handling during buffer deallocation can cause memory corruption. Attackers could exploit this...

CVE-2025-47345

HIGH CVSS 8.4 Jan 7, 2026

A cryptographic vulnerability in license data encryption could allow attackers to decrypt or manipulate license information. This affects systems using Qualcomm components with vulnerable encryption i...

CVE-2025-47346

HIGH CVSS 7.8 Jan 7, 2026

This vulnerability involves memory corruption in the trusted application's secure logging command processing, which could allow attackers to execute arbitrary code or cause denial of service. It affec...

CVE-2025-47348

HIGH CVSS 7.8 Jan 7, 2026

This vulnerability allows memory corruption in the trusted application when processing identity credential operations, potentially leading to arbitrary code execution or system compromise. It affects ...

CVE-2025-47339

HIGH CVSS 7.8 Jan 7, 2026

This vulnerability involves memory corruption during HDCP session deinitialization, potentially allowing attackers to execute arbitrary code or cause denial of service. It affects systems using Qualco...

CVE-2025-47382

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption in the boot loader when loading invalid firmware, potentially enabling attackers to execute arbitrary code or cause denial of service. It affects devices us...

CVE-2025-47320

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption during MFC channel configuration while playing music, potentially enabling arbitrary code execution. It affects devices with Qualcomm chipsets that use the ...

CVE-2025-47321

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability involves memory corruption when copying packets from Unix domain socket clients, potentially allowing attackers to execute arbitrary code or cause denial of service. It affects syst...

CVE-2025-47323

HIGH CVSS 7.8 Dec 18, 2025

This vulnerability allows memory corruption when handling large GPR packets between user and root contexts in Qualcomm components. Attackers could potentially execute arbitrary code with elevated priv...

CVE-2025-27053

HIGH CVSS 7.8 Oct 9, 2025

This vulnerability allows memory corruption in Qualcomm's PlayReady APP implementation when processing TA commands, potentially enabling arbitrary code execution. It affects devices with Qualcomm chip...

CVE-2025-27052

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption in the diag component when processing data packets from Unix clients. Attackers could potentially execute arbitrary code or cause denial of service on affec...

CVE-2025-27043

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption in Qualcomm video firmware when processing manipulated payloads. Attackers could potentially execute arbitrary code or cause denial of service. Affects devi...

CVE-2025-21446

HIGH CVSS 7.5 Jul 8, 2025

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm wireless LAN (WLAN) chipsets when processing vendor-specific information elements in BTM (BSS Transition Management) request f...

CVE-2025-21422

HIGH CVSS 7.1 Jul 8, 2025

This cryptographic vulnerability in Qualcomm chipsets allows improper handling of cryptographic API calls, potentially leading to key corruption or IV reuse. This affects devices using vulnerable Qual...

CVE-2025-21432

HIGH CVSS 7.8 Jul 8, 2025

This vulnerability allows memory corruption when retrieving CBOR data from a Trusted Application (TA) in Qualcomm components. Attackers could potentially execute arbitrary code or cause denial of serv...

CVE-2025-27038

HIGH CVSS 7.5 Jun 3, 2025

This vulnerability allows memory corruption in Chrome's graphics rendering through Adreno GPU drivers, potentially enabling arbitrary code execution. It affects Chrome users on devices with Qualcomm A...

CVE-2025-47371

MEDIUM CVSS 6.5 Mar 2, 2026

This vulnerability allows a denial-of-service (DoS) attack against LTE user equipment (UE) when it receives an RLC packet with an invalid transport block (TB). Mobile devices using affected Qualcomm c...

CVE-2025-47369

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability allows information disclosure when a weak hashed value is returned to userland code in response to an IOCTL call to obtain a session ID. Attackers can potentially extract sensitive ...

CVE-2025-47334

MEDIUM CVSS 6.7 Jan 7, 2026

This vulnerability involves memory corruption in Qualcomm camera drivers when processing shared command buffer packets between userspace and kernel. It allows attackers with camera access to potential...

CVE-2025-47335

MEDIUM CVSS 6.7 Jan 7, 2026

This CVE describes a memory corruption vulnerability in Qualcomm hardware clock configuration parsing. Attackers could potentially execute arbitrary code or cause denial of service by sending speciall...

CVE-2025-47337

MEDIUM CVSS 6.7 Jan 7, 2026

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm synchronization objects that can lead to memory corruption during concurrent operations. Attackers could potentially exploit thi...

CVE-2025-47344

MEDIUM CVSS 6.7 Jan 7, 2026

This CVE describes a memory corruption vulnerability in Qualcomm sensor utility operations that could allow attackers to execute arbitrary code or cause denial of service. The vulnerability affects de...

CVE-2025-47330

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to vulnerable systems. It affects devices using Qualcomm video firmware co...

CVE-2025-47331

MEDIUM CVSS 6.1 Jan 7, 2026

This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects devices using vulnerable Qualcomm chipsets, potent...

CVE-2025-47332

MEDIUM CVSS 6.7 Jan 7, 2026

This vulnerability involves memory corruption when processing configuration calls from userspace in Qualcomm components, potentially allowing local attackers to execute arbitrary code or cause denial ...

CVE-2025-47333

MEDIUM CVSS 6.6 Jan 7, 2026

This vulnerability allows memory corruption in Qualcomm's cryptographic driver when handling buffer mapping operations. Attackers could potentially execute arbitrary code or cause denial of service. A...

CVE-2025-47319

MEDIUM CVSS 6.7 Dec 18, 2025

This vulnerability exposes internal Trusted Application (TA) communication APIs to the High-Level Operating System (HLOS), allowing unauthorized access to sensitive information exchanged between TAs. ...