|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 7, 2026, 12:09 p.m.
Update Date:May 7, 2026, 4:22 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 210171 | 7.0 |
HIGH
Local |
qualcomm |
apq8009_firmware apq8009w_firmware apq8017_firmware apq8053_firmware apq8076_firmware apq8096au_firmware csr6030_firmware mdm9206_firmware mdm9230_firmware mdm9250_firmware… |
Time-of-check time-of-use race condition While processing partition entries due to newly created buffer was read again from mmc without validation in Snapdragon Auto, Snapdragon Connectivity, Snapdra… |
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition |
CVE-2020-11233 | 2024-11-21 13:57 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 210172 | 7.0 |
HIGH
Local |
qualcomm |
apq8009w_firmware apq8017_firmware apq8053_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csr8811_firmware csra6620_firmware csra6640_firmware fsm10055_firmware<… |
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, S… |
CWE-362 CWE-416 Race Condition Use After Free |
CVE-2020-11250 | 2024-11-21 13:57 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 210173 | 7.8 |
HIGH
Local |
qualcomm |
apq8009w_firmware apq8017_firmware apq8053_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware msm8909w_firmwar… |
Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy of the user argument in Snapdragon Auto, Snapdragon Compute, … |
CWE-131
Incorrect Calculation of Buffer Size |
CVE-2020-11240 | 2024-11-21 13:57 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 210174 | 9.8 |
CRITICAL
Network |
qualcomm |
aqt1000_firmware pm3003a_firmware pm4125_firmware pm456_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6250_firmware pm6350_firmware pm640a… |
Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Sna… |
CWE-787
Out-of-bounds Write |
CVE-2020-11182 | 2024-11-21 13:57 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 210175 | 7.8 |
HIGH
Local |
qualcomm |
aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fsm10055_firmware fsm10056_firmware mdm9205_firmware pm3003a_firmwar… |
Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdrag… |
CWE-20
Improper Input Validation |
CVE-2020-11178 | 2024-11-21 13:57 | 2021-06-9 | Show | GitHub Exploit DB Packet Storm |
| 210176 | 7.8 |
HIGH
Local |
qualcomm |
fsm10055_firmware fsm10056_firmware pm3003a_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6350_firmware pm660_firmware pm660l_firmware pm7… |
Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO… |
CWE-416
Use After Free |
CVE-2020-11295 | 2024-11-21 13:57 | 2021-05-7 | Show | GitHub Exploit DB Packet Storm |
| 210177 | 7.8 |
HIGH
Local |
qualcomm |
aqt1000_firmware ar8035_firmware pm3003a_firmware pm4125_firmware pm4250_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6350_firmware pm640… |
Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusted source of input for secure boot loader in Snapdragon Auto… |
CWE-667
Improper Locking |
CVE-2020-11284 | 2024-11-21 13:57 | 2021-05-7 | Show | GitHub Exploit DB Packet Storm |
| 210178 | 7.8 |
HIGH
Local |
qualcomm |
ar8035_firmware pm215_firmware pm3003a_firmware pm6125_firmware pm6150_firmware pm6150a_firmware pm6150l_firmware pm6350_firmware pm640a_firmware pm640l_firmware pm640p_… |
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
CWE-129
Improper Validation of Array Index |
CVE-2020-11294 | 2024-11-21 13:57 | 2021-05-7 | Show | GitHub Exploit DB Packet Storm |
| 210179 | 7.8 |
HIGH
Local |
qualcomm |
apq8009_firmware apq8017_firmware apq8037_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar8151_firmware | Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industr… |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2020-11289 | 2024-11-21 13:57 | 2021-05-7 | Show | GitHub Exploit DB Packet Storm |
| 210180 | 9.8 |
CRITICAL
Network |
qualcomm |
apq8009_firmware apq8009w_firmware apq8017_firmware apq8037_firmware apq8053_firmware apq8084_firmware apq8096au_firmware aqt1000_firmware ar6003_firmware ar8151_firmware | Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
CWE-190
Integer Overflow or Wraparound |
CVE-2020-11279 | 2024-11-21 13:57 | 2021-05-7 | Show | GitHub Exploit DB Packet Storm |