« Volver al listado

Qualcomm

Qualcomm Qca9379 Firmware: vulnerabilidades y CVE

Qualcomm Qca9379 Firmware tiene 246 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 80 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE246
Últimos 12 meses1
Críticas80
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-11261Alta (7.8)1.6%⚠ Explotación activa9 jun 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1905Alta (7.8)1.5%⚠ Explotación activa7 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21433Media (5.5)0.08%—8 jul 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21428Alta (7.5)0.25%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-43052Alta (7.8)0.10%—2 dic 2024
Memory corruption while processing API calls to NPU with invalid input.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-23357Media (5.5)0.09%—5 ago 2024
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2024-21468Alta (7.8)0.11%—1 abr 2024
Memory corruption when there is failed unmap operation in GPU.
CVE-2023-33023Alta (7.8)0.11%—1 abr 2024
Memory corruption while processing finish_sign command to pass a rsp buffer.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-28586Media (6.5)0.14%—5 dic 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28546Alta (7.8)0.11%—5 dic 2023
Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-28572Alta (8.8)0.40%—7 nov 2023
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
CVE-2023-24850Alta (7.8)0.11%—3 oct 2023
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
CVE-2023-33021Alta (7.8)0.12%—5 sept 2023
Memory corruption in Graphics while processing user packets for command submission.
CVE-2023-33020Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
CVE-2023-33019Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
CVE-2023-28565Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2023-28537Alta (7.8)0.12%—8 ago 2023
Memory corruption while allocating memory in COmxApeDec module in Audio.
CVE-2023-22666Alta (7.8)0.12%—8 ago 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21626Alta (7.1)0.11%—8 ago 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Crítica (9.8)0.43%—8 ago 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter4
  2. T1068 Exploitation for Privilege Escalation4
  3. T1190 Exploit Public-Facing Application1
  4. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm