« Volver al listado

Qualcomm

Qualcomm Snapdragon 780g 5G Mobile Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 780g 5G Mobile Platform Firmware tiene 103 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 9 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE103
Últimos 12 meses2
Críticas9
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33106Alta (7.8)0.79%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27034Crítica (9.8)0.40%—24 sept 2025
Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21481Alta (7.8)0.07%—24 sept 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-27062Alta (7.8)0.08%—6 ago 2025
Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2025-21477Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing CCCH data when NW sends data with invalid length.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21452Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53010Alta (7.8)0.08%—3 jun 2025
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2025-21448Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2024-45551Media (6.2)0.11%—7 abr 2025
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
CVE-2024-43046Media (5.5)0.11%—7 abr 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044Alta (7.8)0.10%—2 dic 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38415Alta (7.8)0.10%—4 nov 2024
Memory corruption while handling session errors from firmware.
CVE-2024-38408Crítica (9.1)0.14%—4 nov 2024
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-33043Media (5.5)0.09%—2 sept 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23364Alta (7.5)0.30%—2 sept 2024
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-23362Alta (7.1)0.12%—2 sept 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359Alta (8.2)0.26%—2 sept 2024
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-33023Alta (7.8)0.11%—5 ago 2024
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation11
  2. T1190 Exploit Public-Facing Application11
  3. T1059 Command and Scripting Interpreter10
  4. T1005 Data from Local System4
  5. T1499.004 Application or System Exploitation3
  6. T1040 Network Sniffing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm