Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.88% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096 Firmware+51 | 5/3/2020 | 17/6/2026 | Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cmd in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,… | |
| Modificada | Crítica (9.1) | 0.88% | — | Qualcomm Mdm9206 FirmwareQualcomm Mdm9607 FirmwareQualcomm Mdm9640 FirmwareQualcomm Mdm9650 Firmware+36 | 5/3/2020 | 17/6/2026 | Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917,… | |
| Modificada | Alta (7.5) | 0.81% | — | Qualcomm Msm8905 FirmwareQualcomm Msm8909 FirmwareQualcomm Msm8917 FirmwareQualcomm Msm8920 Firmware+18 | 5/3/2020 | 17/6/2026 | Null pointer dereference issue can happen due to improper validation of CSEQ header response received from network in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953,… | |
| Modificada | Crítica (9.8) | 0.90% | — | Qualcomm Apq8096 FirmwareQualcomm Apq8096au FirmwareQualcomm Ipq6018 FirmwareQualcomm Ipq8074 Firmware+33 | 5/3/2020 | 17/6/2026 | Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and… | |
| Modificada | Media (6.8) | 0.43% | — | GE Vivid E95 FirmwareGE Vivid E90 FirmwareGE Vivid S70n FirmwareGE Vivid T8 Firmware+12 | 20/2/2020 | 17/6/2026 | A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products:… | |
| Modificada | Crítica (9.1) | 0.88% | — | Qualcomm Ipq4019 FirmwareQualcomm Ipq6018 FirmwareQualcomm Ipq8064 FirmwareQualcomm Ipq8074 Firmware+16 | 7/2/2020 | 17/6/2026 | Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074,… | |
| Modificada | Alta (7.8) | 0.20% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8098 Firmware+46 | 7/2/2020 | 17/6/2026 | Uninitialized stack data gets used If memory is not allocated for blob or if the allocated blob is less than the struct size required due to lack of check of return value for read or write blob in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… | |
| Modificada | Crítica (9.1) | 0.88% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8064 Firmware+44 | 7/2/2020 | 17/6/2026 | Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in… | |
| Modificada | Alta (7.8) | 0.22% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+34 | 7/2/2020 | 17/6/2026 | Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | |
| Modificada | Alta (7.8) | 0.43% | 💥 PoC | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+39 | 7/2/2020 | 17/6/2026 | During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Apq8053 FirmwareQualcomm Apq8096au FirmwareQualcomm Apq8098 FirmwareQualcomm Msm8909w Firmware+25 | 7/2/2020 | 17/6/2026 | APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MSM8909W, MSM8917, MSM8920, MSM8937,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8064 Firmware+43 | 7/2/2020 | 17/6/2026 | Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009,… | |
| Modificada | Alta (7.8) | 0.25% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+44 | 7/2/2020 | 17/6/2026 | There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing commands could allow unintended GPU opcodes to be executed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | |
| Modificada | Crítica (9.8) | 1.6% | — | Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+6 | 22/1/2020 | 17/6/2026 | The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. | |
| Modificada | Media (6.5) | 0.81% | — | Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+6 | 22/1/2020 | 17/6/2026 | The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based… | |
| Modificada | Alta (7.5) | 1.2% | — | Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+6 | 22/1/2020 | 17/6/2026 | Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path. | |
| Modificada | Alta (7.5) | 1.4% | — | Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+6 | 22/1/2020 | 17/6/2026 | The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. | |
| Modificada | Alta (7.8) | 0.20% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8053 FirmwareQualcomm Msm8909w FirmwareQualcomm Msm8917 Firmware+23 | 21/1/2020 | 17/6/2026 | Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, MSM8909W, MSM8917, MSM8953,… | |
| Modificada | Alta (7.8) | 0.20% | — | Qualcomm Msm8917 FirmwareQualcomm Msm8953 FirmwareQualcomm Nicobar FirmwareQualcomm Qm215 Firmware+13 | 21/1/2020 | 17/6/2026 | Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile in MSM8917, MSM8953, Nicobar, QM215, Rennell, SDM429, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130 | |
| Modificada | Alta (7.8) | 0.20% | — | Qualcomm Mdm9607 FirmwareQualcomm Nicobar FirmwareQualcomm Rennell FirmwareQualcomm Sa6155p Firmware+6 | 21/1/2020 | 17/6/2026 | String format issue will occur while processing HLOS data as there is no user input validation to ensure inputs are properly NULL terminated before string copy in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, Rennell, SA6155P,… | |
| Modificada | Crítica (9.8) | 0.90% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8064 Firmware+42 | 21/1/2020 | 17/6/2026 | Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables… | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8064 Firmware+37 | 21/1/2020 | 17/6/2026 | Integer overflow occurs while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU,… | |
| Modificada | Crítica (9.8) | 0.90% | — | Qualcomm Nicobar FirmwareQualcomm Sdm670 FirmwareQualcomm Sdm710 FirmwareQualcomm Sdm845 Firmware+4 | 21/1/2020 | 17/6/2026 | Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicobar, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR2130 | |
| Modificada | Crítica (9.8) | 0.91% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8064 Firmware+43 | 21/1/2020 | 17/6/2026 | While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read into the table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | |
| Modificada | Alta (7.5) | 0.66% | — | Qualcomm Mdm9607 FirmwareQualcomm Nicobar FirmwareQualcomm Rennell FirmwareQualcomm Sa6155p Firmware+7 | 21/1/2020 | 17/6/2026 | The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map which happens to be at same physical address in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar,… |