Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qualcomm, Inc.

First CVE: Jul 14, 1998Active for: 28 yearsTotal CVEs: 2,509
55.3
VTI Score
TOP TARGET

Qualcomm's vulnerability footprint spans an exceptionally broad portfolio of mobile system-on-chip processors, wireless connectivity components, and firmware that sit at the foundation of billions of smartphones, IoT devices, and embedded systems, presenting one of the largest and most pervasive attack surfaces in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged execution context and memory access granted to firmware and radio-stack components. The exposure recurs across product lines such as the WCD audio codec and WSA wireless modules through memory-safety weakness classes including out-of-bounds reads and writes, buffer overflows, use-after-free conditions, and improper bounds checking—flaw types characteristic of native firmware and signal-processing code where direct hardware interaction and tight resource constraints limit defensive abstractions. The ubiquity and depth of Qualcomm's silicon in deployed devices means that high-severity flaws in these components can affect entire device populations and require coordination across multiple vendors for remediation. Defenders should treat Qualcomm silicon advisories as broadly applicable to the mobile and embedded ecosystem; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
2,509
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Qualcomm, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 1998
28 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Self-Reporting Analysis

Of all the CVEs published by Qualcomm, Inc. as a CNA, 80.3% affect products that Qualcomm, Inc. develops as a vendor.

80.3%
19.7%
Self-reported: 2,435 (80.3%)
Third-party: 598 (19.7%)

Of all the CVEs published that affect products developed by Qualcomm, Inc., 97.1% are self-published by Qualcomm, Inc. as a CNA.

97.1%
Self-published: 2,435 (97.1%)
Other CNAs: 74 (2.9%)

Products(3,629 total)

Top CVEs

Signals from CVEs in this vendor scope (2509 CVEs).

2,509 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-4267HIGH
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character, as demonstrated usin
Dec 21, 20057.574NOYES
CVE-2026-21385HIGH
Memory corruption while using alignments for memory allocation.
Mar 2, 20267.873YESNO
CVE-2025-21479HIGH
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Jun 3, 20258.669YESNO
CVE-2025-21480HIGH
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Jun 3, 20258.667YESNO
CVE-2021-1905HIGH
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon
May 7, 20217.867YESNO
CVE-2024-43047HIGH
Memory corruption while maintaining memory maps of HLOS memory.
Oct 7, 20247.865YESNO
CVE-2025-27038HIGH
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Jun 3, 20257.564YESNO
CVE-2023-33063HIGH
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Dec 5, 20237.864YESNO
CVE-2023-33107HIGH
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Dec 5, 20237.863YESNO
CVE-2013-2596HIGH
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows
Apr 13, 20137.863YESNO
View all 2,509 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products2,509 CVEs
15%
63%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,433 (57.1%)
Network956 (38.1%)
Unknown49 (2.0%)
Physical25 (1.0%)
Adjacent Network46 (1.8%)
Attack Complexity
Low2,369 (94.4%)
High91 (3.6%)
Unknown49 (2.0%)
User Interaction
None2,439 (97.2%)
Unknown49 (2.0%)
Required21 (0.8%)
Privileges Required
Low1,347 (53.7%)
High79 (3.1%)
None1,034 (41.2%)
Unknown49 (2.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (2509 CVEs).

CISA KEV
13 CVEs
0.5% of CVEs· 99th percentile
Metasploit
1 CVE
0.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
1.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qualcomm, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qualcomm, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qualcomm, Inc.'s Products

View all 5 CNAs →

Top CWEs