Qualcomm Security Vulnerabilities (CVEs)

Track 645 security vulnerabilities affecting Qualcomm products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

101 Critical
476 High
68 Medium
🔔 Get Alerts for Qualcomm
CVE-2024-33048 7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon or probe response frames to aff...

Sep 2, 2024
CVE-2024-33045 8.4

This vulnerability allows memory corruption when the BTFM client sends new messages over Slimbus to the ADSP in Qualcomm chipsets. Attackers could pot...

Sep 2, 2024
CVE-2024-33042 7.8

CVE-2024-33042 is a memory corruption vulnerability in Qualcomm chipsets that occurs when the Alternative Frequency offset value is set to 255. This c...

Sep 2, 2024
CVE-2024-33035 8.4

This vulnerability allows memory corruption in Qualcomm's gralloc memory allocator when clients request extremely high reserved sizes. Attackers could...

Sep 2, 2024
CVE-2024-23365 8.4

CVE-2024-23365 is a use-after-free vulnerability in Qualcomm's MinkSocket component that allows memory corruption when releasing shared resources. Suc...

Sep 2, 2024
CVE-2024-23362 7.1

This vulnerability involves a cryptographic issue in RSA key parsing in COBR format, potentially allowing attackers to bypass cryptographic protection...

Sep 2, 2024
CVE-2024-23358 7.5

This vulnerability in Qualcomm modems allows a transient denial-of-service (DoS) condition when the device receives a registration accept OTA (Over-Th...

Sep 2, 2024
CVE-2024-33028 8.4

This CVE describes a use-after-free vulnerability in Qualcomm graphics drivers where a fence object may still be accessed after being released during ...

Aug 5, 2024
CVE-2024-33026 7.5

This vulnerability allows an attacker to cause a denial-of-service condition in affected Qualcomm Wi-Fi components by sending specially crafted probe ...

Aug 5, 2024
CVE-2024-33024 7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted Wi-Fi beacon frames with malformed Multi-Link (M...

Aug 5, 2024
CVE-2024-33022 8.4

This vulnerability allows memory corruption in the HGSL driver when allocating memory, potentially leading to arbitrary code execution or system crash...

Aug 5, 2024
CVE-2024-33020 7.5

This vulnerability in Qualcomm chipsets allows attackers to cause a denial-of-service condition by sending specially crafted TID-to-link mapping IE el...

Aug 5, 2024
CVE-2024-33018 7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted TID-to-link mapping action frames to a...

Aug 5, 2024
CVE-2024-33014 7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted beacon or probe response frames containing malfo...

Aug 5, 2024
CVE-2024-33012 7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Wi-Fi systems by sending specially crafted beacon frames with malf...

Aug 5, 2024
CVE-2024-33010 7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted MBSSID Information Element fragments in ...

Aug 5, 2024
CVE-2024-23383 8.4

CVE-2024-23383 is a use-after-free vulnerability in Qualcomm kernel drivers that allows memory corruption when hardware fences are triggered. This cou...

Aug 5, 2024
CVE-2024-23381 8.4

This vulnerability involves memory corruption when GPU SMMU fails to unmap memory mapped in a Vertex Buffer Object (VBO), potentially allowing attacke...

Aug 5, 2024
CVE-2024-23357 6.2

This vulnerability allows an attacker to cause a denial of service (DoS) by providing a specially crafted PKCS#8-encoded RSA key with a zero-byte modu...

Aug 5, 2024
CVE-2024-23355 7.8

This vulnerability allows memory corruption in Qualcomm's keymaster component when importing shared keys, potentially leading to arbitrary code execut...

Aug 5, 2024
CVE-2024-23352 7.5

This vulnerability allows attackers to cause a denial of service (DoS) in NAS (Network Access Stratum) implementations by sending specially crafted OD...

Aug 5, 2024
CVE-2024-23350 6.5

This vulnerability allows attackers to cause a permanent denial-of-service condition in Qualcomm cellular modems by sending specially crafted NAS tran...

Aug 5, 2024
CVE-2024-21479 7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a buffer over-read (CWE-126) in Apple Lossless Audio Co...

Aug 5, 2024
CVE-2024-21467 6.5

This vulnerability allows information disclosure when handling beacon probe frames during scan entry generation on client devices. It affects devices ...

Aug 5, 2024
CVE-2024-23373 8.4

This vulnerability allows memory corruption when IOMMU unmap operations fail, leading to improper release of DMA and anonymous buffers. It affects sys...

Jul 1, 2024
CVE-2024-23368 7.8

This CVE describes a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that could allow attackers to execute arbitrary code...

Jul 1, 2024
CVE-2024-21469 7.3

This vulnerability involves memory corruption when an invoke call and a TEE (Trusted Execution Environment) call target the same trusted application s...

Jul 1, 2024
CVE-2024-21466 6.5

This vulnerability allows information disclosure when parsing sub-IE length during new IE generation in Qualcomm components. It affects devices using ...

Jul 1, 2024
CVE-2024-21462 7.1

This vulnerability allows a denial-of-service attack when loading Trusted Application (TA) ELF files on Qualcomm chipsets. It affects devices using Qu...

Jul 1, 2024
CVE-2024-21460 7.1

This vulnerability in Qualcomm chipsets allows information disclosure when Address Space Layout Randomization (ASLR) fails to properly randomize memor...

Jul 1, 2024
CVE-2024-21457 6.5

This vulnerability allows information disclosure when handling Multi-link Information Elements in Wi-Fi beacon frames. It affects devices with Qualcom...

Jul 1, 2024
CVE-2023-43554 8.4

This vulnerability allows memory corruption through improper input validation in FastRPC's IOCTL handler. Attackers could potentially execute arbitrar...

Jul 1, 2024
CVE-2024-23360 8.4

This vulnerability allows memory corruption when creating an LPAC client because the LPAC engine could access GPU registers. It affects devices with Q...

Jun 3, 2024
CVE-2023-43556 9.3

This CVE describes a memory corruption vulnerability in Qualcomm's hypervisor when platform information is not properly aligned. Successful exploitati...

Jun 3, 2024
CVE-2023-43551 9.1

This vulnerability allows a rogue LTE base station to bypass authentication during network attachment, enabling man-in-the-middle attacks. It affects ...

Jun 3, 2024
CVE-2023-43545 6.7

This CVE describes a memory corruption vulnerability in Qualcomm components where sending excessive scan frequency lists or channels from user space c...

Jun 3, 2024
CVE-2023-43543 6.7

This CVE describes a use-after-free vulnerability in Qualcomm audio components where a race condition between allocation and deallocation of graph obj...

Jun 3, 2024
CVE-2023-43538 9.3

This vulnerability allows memory corruption in Qualcomm's TrustZone Secure OS during Tunnel Invoke Manager initialization. Attackers could potentially...

Jun 3, 2024
CVE-2024-23354 8.4

This vulnerability allows memory corruption when an IOCTL call is interrupted by a signal in Qualcomm components, potentially leading to arbitrary cod...

May 6, 2024
CVE-2024-21480 7.3

This vulnerability allows memory corruption when processing audio files with large input buffers, potentially leading to arbitrary code execution. It ...

May 6, 2024
CVE-2024-21476 7.8

CVE-2024-21476 is a memory corruption vulnerability in Qualcomm components where improper validation of user-supplied channel IDs can lead to arbitrar...

May 6, 2024
CVE-2024-21474 8.4

This CVE describes a memory corruption vulnerability in Qualcomm components where a buffer size from a previous function call is reused without proper...

May 6, 2024
CVE-2023-43531 8.4

This vulnerability allows memory corruption during cryptographic key pair generation when verifying serialized headers. It affects systems using Qualc...

May 6, 2024
CVE-2023-43529 7.5

This vulnerability allows attackers to cause a denial-of-service condition in IKEv2 implementations by sending malformed fragment packets. It affects ...

May 6, 2024
CVE-2023-43527 6.8

This vulnerability allows attackers to access sensitive information from memory when parsing dts header atoms in video files. It affects devices using...

May 6, 2024
CVE-2023-43525 6.7

CVE-2023-43525 is a buffer overflow vulnerability in Qualcomm audio drivers that allows memory corruption when copying sound model data from user to k...

May 6, 2024
CVE-2023-43521 6.7

This CVE describes a use-after-free vulnerability in Qualcomm components where registering multiple listeners with the same file descriptor can cause ...

May 6, 2024
CVE-2024-21473 9.8

This vulnerability allows memory corruption when redirecting log files to arbitrary locations with arbitrary filenames in Qualcomm components. It affe...

Apr 1, 2024
CVE-2024-21472 8.4

This vulnerability involves memory corruption in the kernel when handling GPU operations, allowing attackers to potentially execute arbitrary code wit...

Apr 1, 2024
CVE-2024-21468 8.4

CVE-2024-21468 is a use-after-free vulnerability in Qualcomm GPU drivers where failed memory unmapping operations can lead to memory corruption. This ...

Apr 1, 2024

Why Monitor Qualcomm Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 645+ known vulnerabilities affecting Qualcomm products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Qualcomm packages in under 60 seconds. No agents required - completely agentless scanning that works across Qualcomm deployments.

Free vulnerability database: Access detailed information about every Qualcomm CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Qualcomm CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Qualcomm CVEs Free