Codeaurora's vulnerability profile centers on Android MSM (Modem System Module) components that sit within the cellular baseband layer of mobile devices, a foundational but specialized attack surface. The recurring weakness classes—including improper input validation, link-following conditions, memory-buffer boundary issues, and information-disclosure flaws—reflect the parser-intensive and privileged role of modem firmware in handling untrusted radio protocol data, and the vendor's disclosures have a moderate tendency toward confirmed in-the-wild exploitation. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codeaurora over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2597HIGH Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) And | Aug 31, 2014 | 8.4 | 57 | YES | NO |
CVE-2013-2598MEDIUM app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attac | Aug 31, 2014 | 6.6 | 22 | NO | NO |
CVE-2013-4736HIGH Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribution | Feb 10, 2014 | 7.8 | 20 | NO | NO |
CVE-2013-2599MEDIUM A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) relea | Aug 31, 2014 | 5.0 | 19 | NO | NO |
CVE-2013-2595HIGH The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devi | Aug 31, 2014 | 7.2 | 19 | NO | NO |
CVE-2013-4739MEDIUM The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain se | Feb 3, 2014 | 4.9 | 19 | NO | NO |
CVE-2014-0972HIGH The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent | Aug 1, 2014 | 7.2 | 18 | NO | NO |
CVE-2013-4738HIGH Multiple stack-based buffer overflows in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and othe | Feb 3, 2014 | 7.2 | 18 | NO | NO |
CVE-2013-6123MEDIUM Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andro | Jan 14, 2014 | 6.9 | 18 | NO | NO |
CVE-2013-6392MEDIUM The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and o | Nov 30, 2013 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codeaurora.
Media articles that mention a CVE ID that affects a product developed by Codeaurora — matched by CVE ID, not by vendor name.