Qualcomm
Qualcomm Snapdragon 835 Mobile PC Platform Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon 835 Mobile PC Platform Firmware tiene 73 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE73
Últimos 12 meses0
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21483 | Crítica (9.8) | 0.40% | — | 24 sept 2025 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. |
| CVE-2025-21487 | Alta (8.2) | 0.26% | — | 24 sept 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. |
| CVE-2025-21484 | Alta (8.2) | 0.26% | — | 24 sept 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. |
| CVE-2024-53026 | Alta (8.2) | 0.30% | — | 3 jun 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. |
| CVE-2024-53021 | Alta (8.2) | 0.24% | — | 3 jun 2025 | Information disclosure may occur while processing goodbye RTCP packet from network. |
| CVE-2024-53020 | Alta (8.2) | 0.24% | — | 3 jun 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. |
| CVE-2024-53019 | Alta (8.2) | 0.24% | — | 3 jun 2025 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. |
| CVE-2024-53015 | Media (6.6) | 0.09% | — | 3 jun 2025 | Memory corruption while processing IOCTL command to handle buffers associated with a session. |
| CVE-2025-21430 | Alta (7.5) | 0.26% | — | 7 abr 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. |
| CVE-2024-45552 | Alta (8.2) | 0.26% | — | 7 abr 2025 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-23379 | Media (6.7) | 0.11% | — | 7 oct 2024 | Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario. |
| CVE-2024-33043 | Media (5.5) | 0.09% | — | 2 sept 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| CVE-2024-33016 | Media (6.8) | 0.15% | — | 2 sept 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-23362 | Alta (7.1) | 0.12% | — | 2 sept 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
| CVE-2024-33014 | Alta (7.5) | 0.32% | — | 5 ago 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2024-21479 | Alta (7.5) | 0.32% | — | 5 ago 2024 | Transient DOS during music playback of ALAC content. |
| CVE-2024-23380 | Alta (7.8) | 0.16% | — | 1 jul 2024 | Memory corruption while handling user packets during VBO bind operation. |
| CVE-2024-23373 | Alta (7.8) | 0.15% | — | 1 jul 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
| CVE-2024-23368 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-43533 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
| CVE-2023-43519 | Crítica (9.8) | 0.26% | — | 6 feb 2024 | Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. |
| CVE-2023-43518 | Crítica (9.8) | 0.26% | — | 6 feb 2024 | Memory corruption in video while parsing invalid mp2 clip. |
| CVE-2023-33077 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| CVE-2023-33069 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Audio while processing the calibration data returned from ACDB loader. |
| CVE-2023-33068 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Audio while processing IIR config data from AFE calibration block. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.