« Volver al listado

Qualcomm

Qualcomm Pandeiro Firmware: vulnerabilidades y CVE

Qualcomm Pandeiro Firmware tiene 41 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE41
Últimos 12 meses41
Críticas1
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25294Alta (7.4)0.10%—17 sept 2026
Transient DOS while parsing frame during channel usage.
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24081Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-25292Alta (7.6)0.15%—4 ago 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-25289Crítica (9.6)0.19%—4 ago 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25288Alta (7.4)0.16%—4 ago 2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-21384Media (5.3)0.08%—6 jul 2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
CVE-2026-21383Alta (7.1)0.10%—6 jul 2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
CVE-2026-21370Media (5.3)0.08%—6 jul 2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVE-2026-21369Media (5.3)0.08%—6 jul 2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
CVE-2026-21368Media (5.3)0.08%—6 jul 2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2025-59617Alta (7.3)0.09%—6 jul 2026
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616Alta (7.8)0.09%—6 jul 2026
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
CVE-2025-59615Alta (7.8)0.09%—6 jul 2026
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
CVE-2026-25277Alta (8.8)0.07%—1 jun 2026
Memory corruption while using Strongbox due to buffer overflow.
CVE-2026-25276Alta (8.8)0.07%—1 jun 2026
Memory corruption while using Strongbox due to missing bounds check.
CVE-2026-24092Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090Alta (7.1)0.06%—1 jun 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24089Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24087Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot OEM commands.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59606Alta (7.8)0.07%—1 jun 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2026-24082Alta (7.8)0.07%—4 may 2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
CVE-2025-47407Alta (7)0.05%—4 may 2026
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
CVE-2025-47403Alta (7.5)0.22%—4 may 2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47401Alta (7.5)0.22%—4 may 2026
Transient DOS when processing target power rate tables during channel configuration.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation21
  2. T1059 Command and Scripting Interpreter20
  3. T1499.004 Application or System Exploitation7
  4. T1091 Replication Through Removable Media6
  5. T1190 Exploit Public-Facing Application5
  6. T1210 Exploitation of Remote Services4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm