« Volver al listado

Qualcomm

Qualcomm Immersive Home 326 Platform Firmware: vulnerabilidades y CVE

Qualcomm Immersive Home 326 Platform Firmware tiene 78 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE78
Últimos 12 meses6
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25289Crítica (9.6)0.19%—4 ago 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25268Alta (8.8)0.11%—6 jul 2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2025-59609Media (5.5)0.09%—1 jun 2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-27064Media (6.1)0.08%—4 nov 2025
Information disclosure while registering commands from clients with diag through diagHal.
CVE-2025-47328Alta (7.5)0.22%—24 sept 2025
Transient DOS while processing power control requests with invalid antenna or stream values.
CVE-2025-47326Alta (7.5)0.24%—24 sept 2025
Transient DOS while handling command data during power control processing.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27065Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing a frame with malformed shared-key descriptor.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-27029Alta (7.5)0.24%—3 jun 2025
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
CVE-2025-21463Alta (7.5)0.23%—3 jun 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2025-21435Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing extended IE in beacon.
CVE-2024-45556Media (6.5)0.09%—7 abr 2025
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
CVE-2024-43046Media (5.5)0.11%—7 abr 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33063Alta (7.5)0.26%—2 dic 2024
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33068Media (6.5)0.25%—4 nov 2024
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-38397Alta (7.5)0.32%—7 oct 2024
Transient DOS while parsing probe response and assoc response frame.
CVE-2024-33073Alta (8.2)0.35%—7 oct 2024
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33066Crítica (9.8)0.60%—7 oct 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2024-33049Alta (7.5)0.32%—7 oct 2024
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23364Alta (7.5)0.30%—2 sept 2024
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-33026Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-33025Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33024Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
CVE-2024-33019Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the received TID-to-link mapping action frame.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application12
  2. T1499.004 Application or System Exploitation9
  3. T1068 Exploitation for Privilege Escalation4
  4. T1059 Command and Scripting Interpreter2
  5. T1005 Data from Local System1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm