« Volver al listado

Qualcomm

Qualcomm Cologne Firmware: vulnerabilidades y CVE

Qualcomm Cologne Firmware tiene 59 vulnerabilidades publicadas, 59 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE59
Últimos 12 meses59
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25294Alta (7.4)0.10%—17 sept 2026
Transient DOS while parsing frame during channel usage.
CVE-2026-25290Alta (7.8)0.07%—17 sept 2026
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2026-25284Alta (7.3)0.07%—17 sept 2026
Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25283Alta (8.8)0.07%—17 sept 2026
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25282Alta (7.9)0.06%—17 sept 2026
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25281Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
CVE-2026-25280Alta (7.8)0.07%—17 sept 2026
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25261Alta (7.8)0.07%—17 sept 2026
Memory corruption while processing rear sensor IOCTL calls.
CVE-2026-24081Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-24075Alta (7)0.06%—17 sept 2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-24074Alta (7.8)0.07%—17 sept 2026
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVE-2026-24073Alta (7.8)0.07%—17 sept 2026
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2025-59607Alta (7.8)0.07%—17 sept 2026
Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-25289Crítica (9.6)0.19%—4 ago 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25288Alta (7.4)0.16%—4 ago 2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24080Alta (7.8)0.10%—4 ago 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24076Media (6.7)0.11%—4 ago 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-25271Alta (7)0.07%—6 jul 2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
CVE-2026-21379Alta (7.8)0.10%—6 jul 2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-25260Alta (7)0.05%—1 jun 2026
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVE-2026-25259Alta (7.8)0.07%—1 jun 2026
Memory corruption while processing multiple IOCTL command for escape operations.
CVE-2026-25258Alta (7.8)0.07%—1 jun 2026
Memory corruption while processing IOCTL calls for escape operations.
CVE-2026-24092Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090Alta (7.1)0.06%—1 jun 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24089Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24087Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot OEM commands.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59614Media (6.7)0.08%—1 jun 2026
Memory Corruption when sending random number generator command with insufficient output buffer size.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation39
  2. T1059 Command and Scripting Interpreter35
  3. T1499.004 Application or System Exploitation8
  4. T1091 Replication Through Removable Media5
  5. T1190 Exploit Public-Facing Application5
  6. T1210 Exploitation of Remote Services5

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm