Qualcomm
Qualcomm Mdm9150 Firmware: vulnerabilidades y CVE
Qualcomm Mdm9150 Firmware tiene 340 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 94 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE340
Últimos 12 meses0
Críticas94
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22071 | Alta (7.8) | 0.46% | ⚠ Explotación activa | 14 jun 2022 | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-30299 | Media (6.7) | 0.12% | — | 22 nov 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. |
| CVE-2023-21654 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory corruption in Audio during playback session with audio effects enabled. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40537 | Crítica (9.8) | 0.36% | — | 10 mar 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40515 | Crítica (9.8) | 0.33% | — | 10 mar 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33242 | Alta (7.8) | 0.14% | — | 10 mar 2023 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-22075 | Media (5.5) | 0.12% | — | 10 mar 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-33280 | Alta (8.8) | 0.33% | — | 12 feb 2023 | Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet. |
| CVE-2022-33248 | Alta (7.8) | 0.13% | — | 12 feb 2023 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. |
| CVE-2022-33243 | Alta (7.8) | 0.11% | — | 12 feb 2023 | Memory corruption due to improper access control in Qualcomm IPC. |
| CVE-2022-33233 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-40520 | Alta (7.8) | 0.70% | — | 9 ene 2023 | Memory corruption due to stack-based buffer overflow in Core |
| CVE-2022-40519 | Media (5.5) | 0.11% | — | 9 ene 2023 | Information disclosure due to buffer overread in Core |
| CVE-2022-40518 | Media (5.5) | 0.11% | — | 9 ene 2023 | Information disclosure due to buffer overread in Core |
| CVE-2022-40517 | Alta (7.8) | 0.14% | — | 9 ene 2023 | Memory corruption in core due to stack-based buffer overflow |
| CVE-2022-40516 | Alta (7.8) | 0.87% | — | 9 ene 2023 | Memory corruption in Core due to stack-based buffer overflow. |
| CVE-2022-33299 | Alta (7.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. |
| CVE-2022-33290 | Alta (7.5) | 0.38% | — | 9 ene 2023 | Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. |
| CVE-2022-33266 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
| CVE-2022-25721 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in video driver due to type confusion error during video playback |
| CVE-2022-25717 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in display due to double free while allocating frame buffer memory |
| CVE-2022-25715 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields |
| CVE-2022-22079 | Media (4.6) | 0.17% | — | 9 ene 2023 | Denial of service while processing fastboot flash command on mmc due to buffer over read |
| CVE-2022-25712 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25711 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25695 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2022-25682 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.