Qualcomm
Qualcomm Msm8909w Firmware: vulnerabilidades y CVE
Qualcomm Msm8909w Firmware tiene 630 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 264 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE630
Últimos 12 meses0
Críticas264
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33107 | Alta (7.8) | 0.89% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-45552 | Alta (8.2) | 0.26% | — | 7 abr 2025 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. |
| CVE-2024-43052 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while processing API calls to NPU with invalid input. |
| CVE-2018-5852 | Alta (7.8) | 0.12% | — | 26 nov 2024 | An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
| CVE-2018-11952 | Alta (7.8) | 0.11% | — | 26 nov 2024 | An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
| CVE-2017-11076 | Crítica (9.8) | 0.35% | — | 26 nov 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2017-9711 | Alta (7.8) | 0.12% | — | 22 nov 2024 | Certain unprivileged processes are able to perform IOCTL calls. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-33052 | Alta (7.8) | 0.13% | — | 2 sept 2024 | Memory corruption when user provides data for FM HCI command control operations. |
| CVE-2024-33043 | Media (5.5) | 0.09% | — | 2 sept 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| CVE-2024-33042 | Alta (7.8) | 0.13% | — | 2 sept 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2023-43551 | Alta (7.5) | 0.26% | — | 3 jun 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| CVE-2024-21468 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-33120 | Alta (7.8) | 0.11% | — | 2 ene 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33030 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in HLOS while running playready use-case. |
| CVE-2023-33107 | Alta (7.8) | 0.89% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-28551 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-22388 | Crítica (9.8) | 0.35% | — | 7 nov 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
| CVE-2023-24849 | Alta (7.5) | 0.30% | — | 3 oct 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| CVE-2023-24848 | Alta (7.5) | 0.30% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-22385 | Crítica (9.8) | 0.35% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2023-33020 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. |
| CVE-2023-33019 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.