« Volver al listado

Qualcomm

Qualcomm Flight RB5 5G Firmware: vulnerabilidades y CVE

Qualcomm Flight RB5 5G Firmware tiene 59 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE59
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24082Alta (7.8)0.07%—4 may 2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47401Alta (7.5)0.22%—4 may 2026
Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-47398Alta (7.8)0.11%—2 feb 2026
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
CVE-2025-47397Alta (7.8)0.11%—2 feb 2026
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
CVE-2025-47366Alta (7.8)0.10%—2 feb 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27052Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing data packets in diag received from Unix clients.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21433Media (5.5)0.08%—8 jul 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21432Alta (7.8)0.09%—8 jul 2025
Memory corruption while retrieving the CBOR data from TA.
CVE-2025-21468Alta (7.8)0.11%—6 may 2025
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
CVE-2025-21467Alta (7.8)0.11%—6 may 2025
Memory corruption while reading the FW response from the shared queue.
CVE-2025-21459Alta (7.5)0.34%—6 may 2025
Transient DOS while parsing per STA profile in ML IE.
CVE-2024-49844Alta (7.8)0.11%—6 may 2025
Memory corruption while triggering commands in the PlayReady Trusted application.
CVE-2025-21424Alta (7.8)0.12%—3 mar 2025
Memory corruption while calling the NPU driver APIs concurrently.
CVE-2024-53024Alta (7.8)0.12%—3 mar 2025
Memory corruption in display driver while detaching a device.
CVE-2024-53014Alta (7.8)0.12%—3 mar 2025
Memory corruption may occur while validating ports and channels in Audio driver.
CVE-2024-43051Media (5.5)0.11%—3 mar 2025
Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-45553Alta (7.8)0.13%—6 ene 2025
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
CVE-2024-38402Alta (7.8)0.16%—2 sept 2024
Memory corruption while processing IOCTL call for getting group info.
CVE-2024-33060Alta (7.8)0.17%—2 sept 2024
Memory corruption when two threads try to map and unmap a single node simultaneously.
CVE-2024-33057Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33050Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33048Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33045Alta (7.8)0.12%—2 sept 2024
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter17
  2. T1068 Exploitation for Privilege Escalation17
  3. T1190 Exploit Public-Facing Application4
  4. T1499.004 Application or System Exploitation4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm