Qualcomm
Qualcomm Mdm9650 Firmware: vulnerabilidades y CVE
Qualcomm Mdm9650 Firmware tiene 778 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 264 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE778
Últimos 12 meses2
Críticas264
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2023-33063 | Alta (7.8) | 0.58% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27074 | Alta (7.8) | 0.09% | — | 4 nov 2025 | Memory corruption while processing a GP command response. |
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-27062 | Alta (7.8) | 0.08% | — | 6 ago 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. |
| CVE-2024-45562 | Alta (7.8) | 0.11% | — | 6 may 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. |
| CVE-2025-21429 | Alta (7.5) | 0.26% | — | 7 abr 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. |
| CVE-2025-21428 | Alta (7.5) | 0.25% | — | 7 abr 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. |
| CVE-2024-43066 | Alta (7.8) | 0.11% | — | 7 abr 2025 | Memory corruption while handling file descriptor during listener registration/de-registration. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2018-11922 | Media (5.5) | 0.23% | — | 26 nov 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-33060 | Alta (7.8) | 0.17% | — | 2 sept 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33014 | Alta (7.5) | 0.32% | — | 5 ago 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. |
| CVE-2024-23373 | Alta (7.8) | 0.15% | — | 1 jul 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
| CVE-2024-23368 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2024-21471 | Alta (7.8) | 0.11% | — | 6 may 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. |
| CVE-2024-21468 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-33023 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption while processing finish_sign command to pass a rsp buffer. |
| CVE-2023-28547 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption in SPS Application while requesting for public key in sorter TA. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-33069 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. |
| CVE-2023-33068 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. |
| CVE-2023-33067 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
| CVE-2023-33065 | Alta (7.1) | 0.11% | — | 6 feb 2024 | Information disclosure in Audio while accessing AVCS services from ADSP payload. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.