« Volver al listado

Qualcomm

Qualcomm Snapdragon 835 Mobile PC Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 835 Mobile PC Platform Firmware tiene 73 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE73
Últimos 12 meses0
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53019Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
CVE-2024-53015Media (6.6)0.09%—3 jun 2025
Memory corruption while processing IOCTL command to handle buffers associated with a session.
CVE-2025-21430Alta (7.5)0.26%—7 abr 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2024-45552Alta (8.2)0.26%—7 abr 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-38423Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-23379Media (6.7)0.11%—7 oct 2024
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
CVE-2024-33043Media (5.5)0.09%—2 sept 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23362Alta (7.1)0.12%—2 sept 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-33014Alta (7.5)0.32%—5 ago 2024
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21479Alta (7.5)0.32%—5 ago 2024
Transient DOS during music playback of ALAC content.
CVE-2024-23380Alta (7.8)0.16%—1 jul 2024
Memory corruption while handling user packets during VBO bind operation.
CVE-2024-23373Alta (7.8)0.15%—1 jul 2024
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
CVE-2024-23368Alta (7.8)0.10%—1 jul 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43533Alta (7.5)0.32%—6 feb 2024
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-43519Crítica (9.8)0.26%—6 feb 2024
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
CVE-2023-43518Crítica (9.8)0.26%—6 feb 2024
Memory corruption in video while parsing invalid mp2 clip.
CVE-2023-33077Alta (7.8)0.11%—6 feb 2024
Memory corruption in HLOS while converting from authorization token to HIDL vector.
CVE-2023-33069Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
CVE-2023-33068Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing IIR config data from AFE calibration block.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application9
  2. T1005 Data from Local System6
  3. T1059 Command and Scripting Interpreter4
  4. T1068 Exploitation for Privilege Escalation4
  5. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm