Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: snapdragon-profiler

Found 95 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25265
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Creation of Temporary File with Insecure Permissions in Qualcomm Software Center

Privilege escalation due to weak configuration while temporary file handling.

Affected products

Snapdragon
  • ==QSCv1.17.1
  • ==QSCv1.25.1
  • ==QSCv1.22.1
  • ==QSCv1.26.0 on Windows
  • ==QSCv1.21.0
  • ==QSCv1.19.1

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25254
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Improper authorization in Qualcomm Software Center

Improper authorization leads to Remote Code Execution via SocketIO interface.

Affected products

Snapdragon
  • ==QSCv1.21.0
  • ==QSCv1.17.1
  • ==QSCv1.19.1

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25264
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Uncontrolled Search Path Element in Qualcomm Software Center

Privilege escalation due to weak configuration during package extraction process.

Affected products

Snapdragon
  • ==QSCv1.17.1
  • ==QSCv1.25.1
  • ==QSCv1.22.1
  • ==QSCv1.26.0 on Windows
  • ==QSCv1.21.0
  • ==QSCv1.19.1

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25262
6.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Write-what-where Condition in Primary Bootloader

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

Affected products

Snapdragon
  • ==MSM8909
  • ==MDM9x07
  • ==MSM8952
  • ==MDM9x55
  • ==SDX50
  • ==MSM8916
  • ==MDM9x45
  • ==MDM9x65

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25255
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 18 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Exposed function in Qualcomm Package Manager and Qualcomm Software Center.

Exposed dangerous function lead to privilege escalation via gRPC server.

Affected products

Snapdragon
  • ==QSCv1.17.1
  • ==QSCv1.21.0
  • ==QPMv3.0.126.7
  • ==QPMv3.0.127.2
  • ==QSCv1.19.1
  • ==QPMv3.0.125.4

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25294
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 5 days, 21 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in WLAN Firmware

Transient DOS while parsing frame during channel usage.

Affected products

Snapdragon
  • ==X1E80100
  • ==WCN6450
  • ==Palawan25
  • ==QMP1000
  • ==WCD9390
  • ==Qualcomm FastConnect 8800 Mobile Connectivity System
  • ==SC8380XP
  • ==SW-only
  • ==SM8650Q
  • ==WSA8835
  • ==WCN8841
  • ==QLN1086BD
  • ==Congo
  • ==WCN7760
  • ==WCN7860
  • ==WSA8855C
  • ==XRV9209
  • ==QXM1093
  • ==WSA8850W
  • ==SM7750P
  • ==QPA1086BD
  • ==SM8845P
  • ==Snapdragon 8 Elite Gen 5
  • ==WCN3988
  • ==CQ7790M
  • ==SM8975
  • ==FastConnect 6900
  • ==SM8635
  • ==SM8950
  • ==WCD9380
  • ==WCN7880
  • ==WCD9395
  • ==Q-7790
  • ==WCD9378
  • ==WCN6755
  • ==SM8750P
  • ==FastConnect 7800
  • ==SM6850
  • ==Snapdragon 8 Elite
  • ==WSA8832
  • ==Snapdragon 7 Gen 4 Mobile Platform
  • ==WSA8830
  • ==WCD9370
  • ==WCD9385
  • ==WSA8850
  • ==WSA8840
  • ==WCN7881
  • ==Snapdragon 8 Gen 5
  • ==SM7675
  • ==SM8735P
  • ==WCN7861
  • ==WSA8845
  • ==WSA8845H
  • ==QXM1094
  • ==SM8635P
  • ==XRV7209
  • ==Pandeiro
  • ==FastConnect 6700
  • ==SM8950P
  • ==CQ7790
  • ==QXM1096
  • ==SM7675P
  • ==QMP2001
  • ==CQ8845S
  • ==Orne
  • ==QXM1095
  • ==MBM715
  • ==QPA1083BD
  • ==SM8975P
  • ==WCD9375
  • ==FastConnect 6200
  • ==QLN1083BD
  • ==Cologne
  • ==SM4875
  • ==Snapdragon 8 Gen 3 Mobile Platform

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24075
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 days, 21 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in Qualcomm IPC

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

Affected products

Snapdragon
  • ==Snapdragon 8c Compute Platform "Poipu Lite"
  • ==Snapdragon 8cx Compute Platform
  • ==Snapdragon X2 Elite
  • ==WCD9340
  • ==FastConnect 6800
  • ==SC8380XP
  • ==WSA8835
  • ==QCA6391
  • ==WSA8815
  • ==QCM5430
  • ==WCD9341
  • ==FastConnect 6900
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==QCA6420
  • ==WCD9380
  • ==IQX7181
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==FastConnect 7800
  • ==WCD9370
  • ==WCD9385
  • ==WSA8830
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WSA8840
  • ==AQT1000
  • ==WCD9378C
  • ==WSA8845H
  • ==WSA8845
  • ==Snapdragon 7c Compute Platform
  • ==Snapdragon 8cx Gen 2 5G Compute Platform
  • ==FastConnect 6700
  • ==WSA8810
  • ==IQX5121
  • ==Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
  • ==QCA6430
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==Snapdragon 8cx Compute Platform "Poipu Pro"
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==WCD9375
  • ==SM6250
  • ==FastConnect 6200
  • ==QCM6490
  • ==Cologne
  • ==QCA0000

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25283
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 days, 22 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Stack-based Buffer Overflow in OOBM

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Affected products

Snapdragon
  • ==Snapdragon X2 Elite
  • ==WSA8840
  • ==WCD9378C
  • ==WSA8845H
  • ==WSA8845
  • ==FastConnect 7800
  • ==Cologne

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-59607
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 days, 22 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Untrusted Pointer Dereference in Windows Compute

Memory Corruption when copying large input data exceeds normal allocation limits.

Affected products

Snapdragon
  • ==WSA8830
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==Snapdragon X2 Elite
  • ==WSA8840
  • ==SC8380XP
  • ==FastConnect 6900
  • ==WCD9378C
  • ==WSA8845H
  • ==WSA8845
  • ==WCD9380
  • ==WSA8835
  • ==FastConnect 7800
  • ==Cologne
  • ==WCD9385

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25261
6.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 days, 22 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Untrusted Pointer Dereference in Camera

Memory corruption while processing rear sensor IOCTL calls.

Affected products

Snapdragon
  • ==Snapdragon X2 Elite
  • ==SC8380XP
  • ==WSA8835
  • ==QCM5430
  • ==FastConnect 6900
  • ==WCD9380
  • ==IQX7181
  • ==WCD9370
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==FastConnect 7800
  • ==WCD9385
  • ==WSA8830
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WSA8840
  • ==WCD9378C
  • ==WSA8845H
  • ==WSA8845
  • ==FastConnect 6700
  • ==IQX5121
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==WCD9375
  • ==QCM6490
  • ==Cologne
  • ==QCA0000

Matching in nixpkgs