« Volver al listado

Qualcomm

Qualcomm Fsm10055 Firmware: vulnerabilidades y CVE

Qualcomm Fsm10055 Firmware tiene 121 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE121
Últimos 12 meses0
Críticas11
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-11261Alta (7.8)1.6%⚠ Explotación activa9 jun 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1906Media (5.5)0.52%⚠ Explotación activa7 may 2021
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1905Alta (7.8)1.5%⚠ Explotación activa7 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-21452Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-23385Media (6.5)0.25%—4 nov 2024
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVE-2024-33045Alta (7.8)0.12%—2 sept 2024
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
CVE-2024-23368Alta (7.8)0.10%—1 jul 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.
CVE-2024-21475Alta (7.8)0.11%—6 may 2024
Memory corruption when the payload received from firmware is not as per the expected protocol size.
CVE-2023-28578Alta (7.8)0.12%—4 mar 2024
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-24847Alta (7.5)0.32%—3 oct 2023
Transient DOS in Modem while allocating DSM items.
CVE-2022-40504Alta (7.5)0.38%—2 may 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
CVE-2022-33213Alta (8.8)0.41%—10 mar 2023
Memory corruption in modem due to buffer overflow while processing a PPP packet
CVE-2022-33233Alta (7.8)0.12%—12 feb 2023
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
CVE-2022-25702Alta (7.5)0.42%—13 dic 2022
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
CVE-2022-25695Alta (7.8)0.13%—13 dic 2022
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-35104Crítica (9.8)0.81%—14 jun 2022
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-35100Alta (7.5)0.60%—14 jun 2022
Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-35071Media (5.5)0.13%—14 jun 2022
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…
CVE-2021-30349Media (6.7)0.16%—14 jun 2022
Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-30342Media (5.9)0.48%—14 jun 2022
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2021-30334Alta (7.8)0.16%—14 jun 2022
Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-30281Alta (7.8)0.16%—14 jun 2022
Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…
CVE-2021-35106Alta (7.8)0.19%—1 abr 2022
Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
CVE-2021-35105Alta (7.8)0.20%—1 abr 2022
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-35088Crítica (9.1)0.85%—1 abr 2022
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
CVE-2021-30331Media (5.5)0.14%—1 abr 2022
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1942Alta (8.8)0.15%—1 abr 2022
Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
CVE-2021-35069Alta (7.8)0.18%—11 feb 2022
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation6
  2. T1059 Command and Scripting Interpreter4
  3. T1499.004 Application or System Exploitation2
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm