Qualcomm
Qualcomm Snapdragon 782g Mobile Platform Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon 782g Mobile Platform Firmware tiene 77 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 4 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE77
Últimos 12 meses19
Críticas4
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21385 | Alta (7.8) | 1.3% | ⚠ Explotación activa | 2 mar 2026 | Memory corruption while using alignments for memory allocation. |
| CVE-2023-33106 | Alta (7.8) | 0.79% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. |
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25275 | Alta (7.5) | 0.19% | — | 17 sept 2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |
| CVE-2026-24084 | Alta (7.5) | 0.25% | — | 4 ago 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. |
| CVE-2026-24079 | Alta (8.1) | 0.21% | — | 4 ago 2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. |
| CVE-2026-24078 | Media (6.5) | 0.17% | — | 4 ago 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. |
| CVE-2026-24077 | Media (6.5) | 0.17% | — | 4 ago 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. |
| CVE-2026-24091 | Alta (7.2) | 0.10% | — | 1 jun 2026 | Memory corruption while processing fastboot commands with improperly formatted input. |
| CVE-2026-24085 | Alta (7.2) | 0.10% | — | 1 jun 2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. |
| CVE-2025-59610 | Media (6.4) | 0.06% | — | 1 jun 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. |
| CVE-2025-59605 | Alta (7.8) | 0.07% | — | 1 jun 2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. |
| CVE-2025-59604 | Alta (7.8) | 0.07% | — | 1 jun 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
| CVE-2025-47392 | Alta (8.8) | 0.17% | — | 6 abr 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. |
| CVE-2025-47389 | Alta (7.8) | 0.10% | — | 6 abr 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. |
| CVE-2026-21385 | Alta (7.8) | 1.3% | ⚠ Explotación activa | 2 mar 2026 | Memory corruption while using alignments for memory allocation. |
| CVE-2025-47386 | Alta (7.8) | 0.07% | — | 2 mar 2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. |
| CVE-2025-47384 | Media (6.5) | 0.11% | — | 2 mar 2026 | Transient DOS when MAC configures config id greater than supported maximum value. |
| CVE-2025-47383 | Alta (7.2) | 0.14% | — | 2 mar 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
| CVE-2025-47379 | Alta (7.8) | 0.07% | — | 2 mar 2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. |
| CVE-2025-47376 | Alta (7.8) | 0.07% | — | 2 mar 2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. |
| CVE-2025-47375 | Alta (7.8) | 0.07% | — | 2 mar 2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33044 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-38415 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while handling session errors from firmware. |
| CVE-2024-38408 | Crítica (9.1) | 0.14% | — | 4 nov 2024 | Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. |
| CVE-2024-33043 | Media (5.5) | 0.09% | — | 2 sept 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| CVE-2024-33023 | Alta (7.8) | 0.11% | — | 5 ago 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. |
| CVE-2024-33014 | Alta (7.5) | 0.32% | — | 5 ago 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. |
| CVE-2024-23357 | Media (5.5) | 0.09% | — | 5 ago 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| CVE-2023-43536 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS while parse fils IE with length equal to 1. |
| CVE-2023-43533 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.