CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-22065

    Last Modified: 21 Nov 2024

    Out of bound read in WLAN HOST due to improper length check can lead to DOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-22064

    Last Modified: 21 Nov 2024

    Possible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.7
    High

    CVE-2021-35116

    Last Modified: 21 Nov 2024

    APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 14 Jun 2022
    6.7
    Medium

    CVE-2021-35098

    Last Modified: 21 Nov 2024

    Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35096

    Last Modified: 21 Nov 2024

    Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.8
    High

    CVE-2021-35094

    Last Modified: 21 Nov 2024

    Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    6.7
    Medium

    CVE-2021-35092

    Last Modified: 21 Nov 2024

    Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    9.3
    Critical

    CVE-2021-35090

    Last Modified: 21 Nov 2024

    Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35087

    Last Modified: 21 Nov 2024

    Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35086

    Last Modified: 21 Nov 2024

    Possible buffer over read due to improper validation of SIB type when processing a NR system Information message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    5.5
    Medium

    CVE-2021-35085

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    5.5
    Medium

    CVE-2021-35084

    Last Modified: 21 Nov 2024

    Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    9.1
    Critical

    CVE-2021-35082

    Last Modified: 21 Nov 2024

    Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-35080

    Last Modified: 21 Nov 2024

    Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 14 Jun 2022
    6.2
    Medium

    CVE-2021-35079

    Last Modified: 21 Nov 2024

    Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35078

    Last Modified: 21 Nov 2024

    Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35076

    Last Modified: 21 Nov 2024

    Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35073

    Last Modified: 21 Nov 2024

    Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    7.8
    High

    CVE-2021-35072

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2022-25651

    Last Modified: 21 Nov 2024

    Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    7.8
    High

    CVE-2022-22103

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22090

    Last Modified: 21 Nov 2024

    Memory corruption in audio due to use after free while managing buffers from internal cache in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 14 Jun 2022
    7.3
    High

    CVE-2022-22087

    Last Modified: 21 Nov 2024

    memory corruption in video due to buffer overflow while parsing mkv clip with no codechecker in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.3
    High

    CVE-2022-22086

    Last Modified: 21 Nov 2024

    Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22085

    Last Modified: 21 Nov 2024

    Memory corruption in video due to buffer overflow while reading the dts file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22084

    Last Modified: 21 Nov 2024

    Memory corruption when extracting qcp audio file due to lack of check on data length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-22083

    Last Modified: 21 Nov 2024

    Denial of service due to memory corruption while extracting ape header from clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22082

    Last Modified: 21 Nov 2024

    Memory corruption due to possible buffer overflow while parsing DSF header with corrupted channel count in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    6.7
    Medium

    CVE-2021-35121

    Last Modified: 21 Nov 2024

    An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    6.7
    Medium

    CVE-2021-35120

    Last Modified: 21 Nov 2024

    Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    5.5
    Medium

    CVE-2021-35119

    Last Modified: 21 Nov 2024

    Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    6.7
    Medium

    CVE-2021-35118

    Last Modified: 21 Nov 2024

    An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35114

    Last Modified: 21 Nov 2024

    Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35111

    Last Modified: 21 Nov 2024

    Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile

    Published: 14 Jun 2022
    7.8
    High

    CVE-2021-35102

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 14 Jun 2022
    7.1
    High

    CVE-2021-35101

    Last Modified: 21 Nov 2024

    Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile

    Published: 14 Jun 2022
    8.2
    High

    CVE-2021-35083

    Last Modified: 21 Nov 2024

    Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-40650

    Last Modified: 21 Nov 2024

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-40649

    Last Modified: 21 Nov 2024

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

    Published: 14 Jun 2022
    6.1
    Medium

    CVE-2022-32286

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). In certain configurations SAML module is vulnerable to Cross Site Scripting (XSS) attacks due to insufficient error message sanitation. This could allow an attacker to execute malicious code by tricking users into accessing a malicious link.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-32285

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML External Entity (XXE) attacks due to insufficient input sanitation. This may allow an attacker to disclose confidential data under certain circumstances.

    Published: 14 Jun 2022
    8.8
    High

    CVE-2022-32262

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to achieve arbitrary code execution.

    Published: 14 Jun 2022
    5.3
    Medium

    CVE-2022-32261

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a misconfiguration in the APT update. This could allow an attacker to add insecure packages to the application.

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2022-32260

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application creates temporary user credentials for UMC (User Management Component) users. An attacker could use these temporary credentials for authentication bypass in certain scenarios.

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2022-32259

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit test scripts with sensitive information. An attacker could gain information about testing architecture and also tamper with test configuration.

    Published: 14 Jun 2022
    5.3
    Medium

    CVE-2022-32258

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains an older feature that allows to import device configurations via a specific endpoint. An attacker could use this vulnerability for information disclosure.

    Published: 14 Jun 2022
    4.3
    Medium

    CVE-2022-32256

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to low privileged users accessing privileged information.

    Published: 14 Jun 2022
    5.3
    Medium

    CVE-2022-32255

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to limited information.

    Published: 14 Jun 2022
    4.3
    Medium

    CVE-2022-32254

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application to write the status of a given user to a log file, exposing sensitive user information that could provide valuable guidance to an attacker.

    Published: 14 Jun 2022
    4.9
    Medium

    CVE-2022-32253

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). Due to improper input validation, the OpenSSL certificate's password could be printed to a file reachable by an attacker.

    Published: 14 Jun 2022