Qualcomm
Qualcomm Mdm9206 Firmware: vulnerabilidades y CVE
Qualcomm Mdm9206 Firmware tiene 737 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 292 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE737
Últimos 12 meses0
Críticas292
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2018-11922 | Media (5.5) | 0.23% | — | 26 nov 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-15832 | Alta (7.8) | 0.12% | — | 26 nov 2024 | Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW |
| CVE-2016-10394 | Alta (7.8) | 0.10% | — | 26 nov 2024 | Initial xbl_sec revision does not have all the debug policy features and critical checks. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-33295 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length. |
| CVE-2022-33294 | Alta (7.5) | 0.38% | — | 13 abr 2023 | Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message. |
| CVE-2022-33259 | Crítica (9.8) | 0.42% | — | 13 abr 2023 | Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received. |
| CVE-2022-33258 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure due to buffer over-read in modem while reading configuration parameters. |
| CVE-2022-33228 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header. |
| CVE-2022-33223 | Alta (7.5) | 0.38% | — | 13 abr 2023 | Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding. |
| CVE-2022-33222 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. |
| CVE-2022-33211 | Crítica (9.8) | 0.42% | — | 13 abr 2023 | memory corruption in modem due to improper check while calculating size of serialized CoAP message |
| CVE-2022-25747 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message |
| CVE-2022-25740 | Crítica (9.8) | 0.42% | — | 13 abr 2023 | Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface |
| CVE-2022-25739 | Alta (7.5) | 0.38% | — | 13 abr 2023 | Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call |
| CVE-2022-25737 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to missing NULL check while reading packets received from local network |
| CVE-2022-25731 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to buffer over-read while processing packets from DNS server |
| CVE-2022-25730 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem due to improper check of IP type while processing DNS server query |
| CVE-2022-25726 | Alta (7.5) | 0.35% | — | 13 abr 2023 | Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet |
| CVE-2022-25678 | Crítica (9.8) | 0.42% | — | 13 abr 2023 | Memory correction in modem due to buffer overwrite during coap connection |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40515 | Crítica (9.8) | 0.33% | — | 10 mar 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-25655 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.