Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Codeaurora

First CVE: Nov 30, 2013Active for: 13 yearsTotal CVEs: 11
41.9
VTI Score
High

Codeaurora's vulnerability profile centers on Android MSM (Modem System Module) components that sit within the cellular baseband layer of mobile devices, a foundational but specialized attack surface. The recurring weakness classes—including improper input validation, link-following conditions, memory-buffer boundary issues, and information-disclosure flaws—reflect the parser-intensive and privileged role of modem firmware in handling untrusted radio protocol data, and the vendor's disclosures have a moderate tendency toward confirmed in-the-wild exploitation. Current severity, exploitation status, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
9.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Codeaurora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2013
12 years ago
Most Recent CVE
Aug 31, 2014
4,345 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2597HIGH
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) And
Aug 31, 20148.457YESNO
CVE-2013-2598MEDIUM
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attac
Aug 31, 20146.622NONO
CVE-2013-4736HIGH
Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribution
Feb 10, 20147.820NONO
CVE-2013-2599MEDIUM
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) relea
Aug 31, 20145.019NONO
CVE-2013-2595HIGH
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devi
Aug 31, 20147.219NONO
CVE-2013-4739MEDIUM
The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain se
Feb 3, 20144.919NONO
CVE-2014-0972HIGH
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent
Aug 1, 20147.218NONO
CVE-2013-4738HIGH
Multiple stack-based buffer overflows in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and othe
Feb 3, 20147.218NONO
CVE-2013-6123MEDIUM
Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andro
Jan 14, 20146.918NONO
CVE-2013-6392MEDIUM
The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and o
Nov 30, 20134.915NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
45%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (9.1%)
Network0 (0.0%)
Unknown10 (90.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (9.1%)
High0 (0.0%)
Unknown10 (90.9%)
User Interaction
None1 (9.1%)
Unknown10 (90.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (9.1%)
Unknown10 (90.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
1 CVE
9.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Codeaurora.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Codeaurora — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Codeaurora's Products

View all 2 CNAs →

Top CWEs