📦 Snapdragon Wear 4100\+ Platform Firmware

by Qualcomm

🔍 What is Snapdragon Wear 4100\+ Platform Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33054

CRITICAL CVSS 9.1 Dec 5, 2023

CVE-2023-33054 is a cryptographic vulnerability in Qualcomm's GPS HLOS driver that allows improper authentication when downloading GNSS assistance data. This affects Android devices with Qualcomm chip...

CVE-2025-27074

HIGH CVSS 8.8 Nov 4, 2025

This vulnerability involves memory corruption while processing a GP command response in Qualcomm components, potentially allowing attackers to execute arbitrary code or cause denial of service. It aff...

CVE-2025-27053

HIGH CVSS 7.8 Oct 9, 2025

This vulnerability allows memory corruption in Qualcomm's PlayReady APP implementation when processing TA commands, potentially enabling arbitrary code execution. It affects devices with Qualcomm chip...

CVE-2025-21482

HIGH CVSS 7.1 Sep 24, 2025

This CVE describes a cryptographic vulnerability in RSA PKCS padding decoding that could allow attackers to decrypt sensitive data or forge digital signatures. It affects Qualcomm products implementin...

CVE-2024-45549

HIGH CVSS 7.7 Apr 7, 2025

This vulnerability allows unauthorized information disclosure when creating MQ channels in affected Qualcomm products. Attackers can potentially access sensitive data that should be protected. This af...

CVE-2024-43052

HIGH CVSS 7.8 Dec 2, 2024

This vulnerability allows memory corruption in Qualcomm NPU (Neural Processing Unit) drivers when processing API calls with invalid input. Attackers could potentially execute arbitrary code or cause d...

CVE-2024-33044

HIGH CVSS 8.4 Dec 2, 2024

This vulnerability allows memory corruption when configuring SMR/S2CR registers in Bypass mode on Qualcomm chipsets. Attackers could potentially execute arbitrary code or cause denial of service. Affe...

CVE-2024-33056

HIGH CVSS 8.4 Dec 2, 2024

CVE-2024-33056 is a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that allows attackers to potentially execute arbitrary code or cause denial of service. This affects de...

CVE-2024-23385

HIGH CVSS 7.5 Nov 4, 2024

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in mobile devices by sending specially crafted MAC RAR messages with invalid PDU lengths, triggering a modem reset. It ...

CVE-2024-23358

HIGH CVSS 7.5 Sep 2, 2024

This vulnerability in Qualcomm modems allows a transient denial-of-service (DoS) condition when the device receives a registration accept OTA (Over-The-Air) message with incorrect ciphering key data. ...

CVE-2024-21479

HIGH CVSS 7.5 Aug 5, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a buffer over-read (CWE-126) in Apple Lossless Audio Codec (ALAC) processing. When a specially crafted AL...

CVE-2024-23373

HIGH CVSS 8.4 Jul 1, 2024

This vulnerability allows memory corruption when IOMMU unmap operations fail, leading to improper release of DMA and anonymous buffers. It affects systems using Qualcomm chipsets with vulnerable IOMMU...

CVE-2023-43513

HIGH CVSS 7.8 Feb 6, 2024

This vulnerability allows memory corruption in Qualcomm hardware components when processing event rings, where an untrusted context read pointer can be manipulated to point to arbitrary memory locatio...

CVE-2023-43519

HIGH CVSS 7.3 Feb 6, 2024

This vulnerability allows memory corruption in video processing when parsing Videoinfo atoms with sizes larger than expected. Attackers could potentially execute arbitrary code or cause denial of serv...

CVE-2023-33110

HIGH CVSS 7.8 Jan 2, 2024

This CVE describes a race condition vulnerability in Qualcomm's PCM host voice audio driver where improper session index handling during event callbacks and PCM close operations can lead to memory cor...

CVE-2023-33070

HIGH CVSS 7.1 Dec 5, 2023

CVE-2023-33070 is a vulnerability in Qualcomm Automotive OS where improper authentication to secure IO calls allows attackers to cause a transient denial-of-service condition. This affects automotive ...

CVE-2023-28551

HIGH CVSS 7.8 Dec 5, 2023

This vulnerability allows memory corruption in Qualcomm modem UTILS when processing Diag commands with arbitrary address values. Attackers could potentially execute arbitrary code or cause denial of s...

CVE-2023-24848

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows information disclosure in Qualcomm data modems during VoLTE calls when an undefined RTCP FB line value is processed. Attackers could potentially access sensitive information ...

CVE-2023-22385

HIGH CVSS 8.2 Oct 3, 2023

This vulnerability allows memory corruption in Qualcomm data modem chipsets during mobile-originated or mobile-terminated VoLTE calls. Attackers could potentially execute arbitrary code or cause denia...

CVE-2023-28537

HIGH CVSS 8.4 Aug 8, 2023

This vulnerability allows memory corruption in Qualcomm's audio processing module (COmxApeDec) due to integer overflow during memory allocation. Attackers could potentially execute arbitrary code or c...

CVE-2022-40521

HIGH CVSS 7.5 Jun 6, 2023

CVE-2022-40521 is an improper authorization vulnerability in Qualcomm modem firmware that allows attackers to cause a transient denial of service (DoS) by sending specially crafted requests. This affe...

CVE-2022-33264

HIGH CVSS 7.9 Jun 6, 2023

CVE-2022-33264 is a stack-based buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when parsing OTASP Key Generation Request Messages. Successful exploitation could...

CVE-2023-21666

HIGH CVSS 8.4 May 2, 2023

CVE-2023-21666 is a memory corruption vulnerability in Qualcomm's Adreno GPU driver (KGSL) that allows attackers to access sensitive data from graphics memory pools. This affects Android devices with ...

CVE-2024-33032

MEDIUM CVSS 6.7 Nov 4, 2024

This CVE describes a memory corruption vulnerability in Qualcomm components where asynchronous modification of shared memory by user applications while the kernel is accessing it can lead to system in...