« Volver al listado

Qualcomm

Qualcomm Snapdragon XR2 5G Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon XR2 5G Firmware tiene 96 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE96
Últimos 12 meses4
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47408Alta (7.8)0.07%—4 may 2026
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
CVE-2025-47407Alta (7)0.05%—4 may 2026
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47405Alta (7.8)0.07%—4 may 2026
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21446Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21433Media (5.5)0.08%—8 jul 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21432Alta (7.8)0.09%—8 jul 2025
Memory corruption while retrieving the CBOR data from TA.
CVE-2025-21427Alta (8.2)0.22%—8 jul 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21422Alta (7.8)0.10%—8 jul 2025
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
CVE-2024-53009Alta (7.8)0.09%—8 jul 2025
Memory corruption while operating the mailbox in Automotive.
CVE-2025-21467Alta (7.8)0.11%—6 may 2025
Memory corruption while reading the FW response from the shared queue.
CVE-2025-21453Alta (7.8)0.11%—6 may 2025
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
CVE-2024-49845Alta (7.8)0.11%—6 may 2025
Memory corruption during the FRS UDS generation process.
CVE-2024-49844Alta (7.8)0.11%—6 may 2025
Memory corruption while triggering commands in the PlayReady Trusted application.
CVE-2024-49842Alta (7.8)0.09%—6 may 2025
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
CVE-2024-49841Alta (7.8)0.11%—6 may 2025
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
CVE-2024-49835Alta (7.8)0.11%—6 may 2025
Memory corruption while reading secure file.
CVE-2024-45570Alta (7.8)0.11%—6 may 2025
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
CVE-2024-45566Alta (7.8)0.11%—6 may 2025
Memory corruption during concurrent buffer access due to modification of the reference count.
CVE-2024-45564Alta (7.8)0.11%—6 may 2025
Memory corruption during concurrent access to server info object due to incorrect reference count update.
CVE-2024-45562Alta (7.8)0.11%—6 may 2025
Memory corruption during concurrent access to server info object due to unprotected critical field.
CVE-2025-21424Alta (7.8)0.12%—3 mar 2025
Memory corruption while calling the NPU driver APIs concurrently.
CVE-2024-53027Alta (7.5)0.30%—3 mar 2025
Transient DOS may occur while processing the country IE.
CVE-2024-53014Alta (7.8)0.12%—3 mar 2025
Memory corruption may occur while validating ports and channels in Audio driver.
CVE-2024-43057Alta (7.8)0.12%—3 mar 2025
Memory corruption while processing command in Glink linux.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation27
  2. T1059 Command and Scripting Interpreter26
  3. T1190 Exploit Public-Facing Application6
  4. T1005 Data from Local System3
  5. T1499.004 Application or System Exploitation3
  6. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm