Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.19% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Mdm9205 Firmware+28 | 21/11/2019 | 17/6/2026 | Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009,… | |
| Modificada | Crítica (9.8) | 0.61% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+51 | 21/11/2019 | 17/6/2026 | Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+51 | 21/11/2019 | 17/6/2026 | Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017,… | |
| Modificada | Alta (7) | 0.13% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+32 | 21/11/2019 | 17/6/2026 | Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,… | |
| Modificada | Alta (7.8) | 0.22% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096 Firmware+51 | 21/11/2019 | 17/6/2026 | Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… | |
| Modificada | Media (6.7) | 0.39% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+126 | 14/11/2019 | 17/6/2026 | Insufficient memory protection in System Management Mode (SMM) and Intel(R) TXT for certain Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Modificada | Alta (8.2) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9615 Firmware+42 | 6/11/2019 | 17/6/2026 | Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9615, MDM9640,… | |
| Modificada | Crítica (9.8) | 1.2% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9615 Firmware+42 | 6/11/2019 | 17/6/2026 | Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 Firmware+40 | 6/11/2019 | 17/6/2026 | Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 Firmware+37 | 6/11/2019 | 17/6/2026 | Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Qualcomm Msm8909w FirmwareQualcomm Msm8996au FirmwareQualcomm Qcs605 FirmwareQualcomm 215 Firmware+32 | 6/11/2019 | 17/6/2026 | Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 Firmware+35 | 6/11/2019 | 17/6/2026 | Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640,… | |
| Modificada | Media (5.5) | 0.19% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9205 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 Firmware+39 | 6/11/2019 | 17/6/2026 | While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key operations are invoked(Depends on CVE-2018-13907) in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9615 FirmwareQualcomm Mdm9625 Firmware+46 | 6/11/2019 | 17/6/2026 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9607, MDM9615, MDM9625, MDM9635M,… | |
| Modificada | Alta (7.8) | 0.20% | — | Qualcomm Mdm9205 FirmwareQualcomm Mdm9640 FirmwareQualcomm Msm8996au FirmwareQualcomm Qca6574 Firmware+29 | 6/11/2019 | 17/6/2026 | Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9205, MDM9640, MSM8996AU, QCA6574, QCS605, Qualcomm 215,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Msm8909w FirmwareQualcomm Msm8996au Firmware+32 | 6/11/2019 | 17/6/2026 | Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, MSM8996AU, QCA6574AU,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Msm8909w FirmwareQualcomm Msm8996au Firmware+35 | 6/11/2019 | 17/6/2026 | Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, MSM8996AU, QCA6574AU,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Msm8909w FirmwareQualcomm Msm8996au Firmware+35 | 6/11/2019 | 17/6/2026 | Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, MSM8996AU, QCA6574AU,… | |
| Modificada | Crítica (9.8) | 0.90% | — | Qualcomm Mdm9607 FirmwareQualcomm Msm8909w FirmwareQualcomm 215 FirmwareQualcomm SD 210 Firmware+9 | 6/11/2019 | 17/6/2026 | Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SDM439 | |
| Modificada | Alta (8.1) | 1.7% | 💥 Exploit | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 Firmware+37 | 6/11/2019 | 17/6/2026 | Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150,… | |
| Modificada | Alta (7.8) | 0.19% | — | Qualcomm Mdm9150 FirmwareQualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 Firmware+37 | 6/11/2019 | 17/6/2026 | Lack of check for a negative value returned for get_clk is wrongly interpreted as valid pointer and lead to use after free in clk driver in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640,… |