Qualcomm
Qualcomm Fsm10055 Firmware: vulnerabilidades y CVE
Qualcomm Fsm10055 Firmware tiene 121 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE121
Últimos 12 meses0
Críticas11
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21452 | Alta (7.5) | 0.21% | — | 6 ago 2025 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. |
| CVE-2025-27061 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| CVE-2025-27042 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption while processing video packets received from video firmware. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-23385 | Media (6.5) | 0.25% | — | 4 nov 2024 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. |
| CVE-2024-33045 | Alta (7.8) | 0.12% | — | 2 sept 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| CVE-2024-23368 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. |
| CVE-2024-21475 | Alta (7.8) | 0.11% | — | 6 may 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| CVE-2023-28578 | Alta (7.8) | 0.12% | — | 4 mar 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. |
| CVE-2023-28551 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-24847 | Alta (7.5) | 0.32% | — | 3 oct 2023 | Transient DOS in Modem while allocating DSM items. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-33233 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-25702 | Alta (7.5) | 0.42% | — | 13 dic 2022 | Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25695 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-35104 | Crítica (9.8) | 0.81% | — | 14 jun 2022 | Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-35100 | Alta (7.5) | 0.60% | — | 14 jun 2022 | Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-35071 | Media (5.5) | 0.13% | — | 14 jun 2022 | Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2021-30349 | Media (6.7) | 0.16% | — | 14 jun 2022 | Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-30342 | Media (5.9) | 0.48% | — | 14 jun 2022 | Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2021-30334 | Alta (7.8) | 0.16% | — | 14 jun 2022 | Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-30281 | Alta (7.8) | 0.16% | — | 14 jun 2022 | Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2021-35106 | Alta (7.8) | 0.19% | — | 1 abr 2022 | Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2021-35105 | Alta (7.8) | 0.20% | — | 1 abr 2022 | Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2021-35088 | Crítica (9.1) | 0.85% | — | 1 abr 2022 | Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2021-30331 | Media (5.5) | 0.14% | — | 1 abr 2022 | Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1942 | Alta (8.8) | 0.15% | — | 1 abr 2022 | Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2021-35069 | Alta (7.8) | 0.18% | — | 11 feb 2022 | Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.