Qualcomm Security Vulnerabilities (CVEs)

Track 645 security vulnerabilities affecting Qualcomm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

101 Critical
476 High
68 Medium
🔔 Get Alerts for Qualcomm
CVE-2024-45557 7.8

This vulnerability allows memory corruption in Qualcomm chipsets when Trusted Execution Environment (TEE) components process untrusted memory addresse...

Apr 7, 2025
CVE-2024-45552 8.2

This vulnerability allows information disclosure during video calls when a device receives a malformed RTCP packet that doesn't conform to RFC standar...

Apr 7, 2025
CVE-2024-45549 7.7

This vulnerability allows unauthorized information disclosure when creating MQ channels in affected Qualcomm products. Attackers can potentially acces...

Apr 7, 2025
CVE-2024-45544 6.6

This vulnerability allows memory corruption through improper handling of IOCTL calls when adding route entries in Qualcomm hardware. Attackers could p...

Apr 7, 2025
CVE-2024-45540 6.6

This vulnerability allows memory corruption through improper handling of IOCTL map buffer requests from userspace. Attackers could potentially execute...

Apr 7, 2025
CVE-2024-43066 7.8

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm components that occurs during file descriptor handling in listener registratio...

Apr 7, 2025
CVE-2024-43058 7.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting memory corruption in IOCTL handling. It affects...

Apr 7, 2025
CVE-2024-33058 7.5

This CVE describes a memory corruption vulnerability in Qualcomm's ADSP (Audio Digital Signal Processor) when handling memory allocation from the HLOS...

Apr 7, 2025
CVE-2025-21424 7.8

This CVE describes a use-after-free vulnerability (CWE-416) in Qualcomm NPU driver APIs that can be triggered through concurrent calls, leading to mem...

Mar 3, 2025
CVE-2024-53033 7.8

This vulnerability allows memory corruption in Qualcomm components when a malicious user provides a kernel address instead of a valid user buffer addr...

Mar 3, 2025
CVE-2024-53031 7.8

This vulnerability allows a malicious guest virtual machine to cause memory corruption in the host system by manipulating type values in a controlled ...

Mar 3, 2025
CVE-2024-53029 7.8

This vulnerability allows a malicious guest virtual machine to trigger memory corruption in the host system by providing specially crafted buffer data...

Mar 3, 2025
CVE-2024-53027 7.5

This vulnerability in Qualcomm components allows a denial-of-service attack when processing country information elements. It affects devices using Qua...

Mar 3, 2025
CVE-2024-53024 7.8

This CVE describes a memory corruption vulnerability in Qualcomm display drivers that occurs when detaching a device. Successful exploitation could al...

Mar 3, 2025
CVE-2024-53022 7.8

This vulnerability involves memory corruption during communication between primary and guest virtual machines in Qualcomm platforms, potentially allow...

Mar 3, 2025
CVE-2024-53012 7.8

This vulnerability allows memory corruption through improper input validation in clock device drivers on Qualcomm chipsets. Attackers could potentiall...

Mar 3, 2025
CVE-2024-49836 7.8

This CVE describes a memory corruption vulnerability in Qualcomm camera frame processing pipeline synchronization. Attackers could potentially execute...

Mar 3, 2025
CVE-2024-43062 7.8

This CVE describes a memory corruption vulnerability in Qualcomm components caused by missing locks and improper synchronization on DMA fences. Attack...

Mar 3, 2025
CVE-2024-43060 7.8

This CVE describes a memory corruption vulnerability in Qualcomm's voice activation system when sound model parameters are transferred from the HLOS (...

Mar 3, 2025
CVE-2024-43057 7.8

CVE-2024-43057 is a use-after-free vulnerability in the Glink Linux driver that allows memory corruption when processing commands. This could enable l...

Mar 3, 2025
CVE-2024-43055 7.8

This CVE describes a memory corruption vulnerability in Qualcomm camera drivers when processing IOCTL calls. Attackers could exploit this to execute a...

Mar 3, 2025
CVE-2024-38426 5.4

This vulnerability in Qualcomm UE (User Equipment) authentication processing allows improper authentication that could lead to information disclosure....

Mar 3, 2025
CVE-2024-49843 7.8

This vulnerability allows memory corruption through improper input validation when processing IOCTL calls related to GPU AHB bus error handling. Attac...

Feb 3, 2025
CVE-2024-49840 7.8

This vulnerability allows memory corruption when user-space applications make IOCTL calls to validate FIPS encryption/decryption functionality. Attack...

Feb 3, 2025
CVE-2024-49839 8.2

This vulnerability allows memory corruption during Wi-Fi management frame processing due to a mismatch in T2LM (Target Wake Time Link Management) info...

Feb 3, 2025
CVE-2024-49838 8.2

This vulnerability allows attackers to read sensitive memory contents when parsing malformed OCI (Oracle Call Interface) information elements with inv...

Feb 3, 2025
CVE-2024-49837 7.8

This vulnerability allows memory corruption during guest virtual machine suspend operations in Qualcomm hypervisors. Attackers could potentially execu...

Feb 3, 2025
CVE-2024-49834 7.8

This vulnerability involves memory corruption during camera sensor power-up or power-down sequences on Qualcomm devices. It could allow attackers to e...

Feb 3, 2025
CVE-2024-49833 7.8

This vulnerability allows memory corruption in Qualcomm camera components when an invalid CID (Camera ID) is used. Attackers could potentially execute...

Feb 3, 2025
CVE-2024-45584 7.8

This vulnerability allows memory corruption when userspace makes a compat IOCTL call followed by a normal IOCTL call, potentially leading to privilege...

Feb 3, 2025
CVE-2024-45582 7.8

This CVE describes a memory corruption vulnerability in the Camera kernel driver when validating the number of devices. Successful exploitation could ...

Feb 3, 2025
CVE-2024-45573 7.8

This vulnerability allows memory corruption through negative indexing of display ID during test pattern generation. It affects systems using Qualcomm ...

Feb 3, 2025
CVE-2024-45569 9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted ML IE frames to affected ...

Feb 3, 2025
CVE-2024-45561 7.8

This vulnerability allows memory corruption when handling IOCTL calls from user-space to set latency levels in Qualcomm components. Attackers could po...

Feb 3, 2025
CVE-2024-45560 7.8

This CVE describes a memory corruption vulnerability in Qualcomm hardware encoders when taking snapshots due to unvalidated userspace buffers. Attacke...

Feb 3, 2025
CVE-2024-38420 8.8

This vulnerability allows memory corruption when configuring a hypervisor-based input virtual device, potentially enabling arbitrary code execution or...

Feb 3, 2025
CVE-2024-38418 7.8

This vulnerability allows memory corruption through improper handling of memory map information in IOCTL calls. Attackers could potentially execute ar...

Feb 3, 2025
CVE-2024-38416 6.1

CVE-2024-38416 is an information disclosure vulnerability in Qualcomm audio components that allows attackers to access sensitive memory contents durin...

Feb 3, 2025
CVE-2024-38413 6.6

This vulnerability allows memory corruption while processing frame packets in Qualcomm components, potentially enabling attackers to execute arbitrary...

Feb 3, 2025
CVE-2024-38411 6.6

This CVE describes a memory corruption vulnerability in Qualcomm components where improper validation of user-space buffers during IOCTL calls allows ...

Feb 3, 2025
CVE-2024-38404 7.5

This vulnerability in Qualcomm modems allows a transient denial-of-service (DoS) condition when the device receives a registration accept message with...

Feb 3, 2025
CVE-2024-45559 5.5

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm's GVM (Guest Virtual Machine) when it sends a specific message type to the V...

Jan 6, 2025
CVE-2024-45558 7.5

This vulnerability in Qualcomm Wi-Fi drivers allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted packets. The d...

Jan 6, 2025
CVE-2024-45555 8.4

This vulnerability allows attackers to bypass boot verification by overwriting an already verified IFS2 image, enabling injection of unauthorized prog...

Jan 6, 2025
CVE-2024-45553 7.8

This CVE describes a use-after-free vulnerability in Qualcomm components where memory corruption can occur when process-specific maps are improperly h...

Jan 6, 2025
CVE-2024-45550 7.8

This vulnerability allows memory corruption through IOCTL calls to the MCDM driver, potentially leading to privilege escalation or system compromise. ...

Jan 6, 2025
CVE-2024-45548 7.8

This vulnerability allows attackers to cause memory corruption through a specific IOCTL call related to FIPS encryption/decryption validation. It affe...

Jan 6, 2025
CVE-2024-45547 7.8

This vulnerability allows memory corruption through a specific IOCTL call when processing FIPS encryption/decryption verification in Qualcomm componen...

Jan 6, 2025
CVE-2024-45546 7.8

This vulnerability allows memory corruption when processing FIPS encryption/decryption IOCTL calls from user-space in Qualcomm components. Attackers c...

Jan 6, 2025
CVE-2024-45542 7.8

This vulnerability allows memory corruption when a user-space application makes a specific IOCTL call to write board data to the WLAN driver. Attacker...

Jan 6, 2025

Why Monitor Qualcomm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 645+ known vulnerabilities affecting Qualcomm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Qualcomm packages in under 60 seconds. No agents required - completely agentless scanning that works across Qualcomm deployments.

Free vulnerability database: Access detailed information about every Qualcomm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Qualcomm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Qualcomm CVEs Free