Qualcomm
Qualcomm Qcs605 Firmware: vulnerabilidades y CVE
Qualcomm Qcs605 Firmware tiene 703 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 197 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE703
Últimos 12 meses0
Críticas197
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-30299 | Media (6.7) | 0.12% | — | 22 nov 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. |
| CVE-2023-33054 | Crítica (9.1) | 0.36% | — | 5 dic 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| CVE-2023-33022 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-33027 | Alta (7.5) | 0.32% | — | 3 oct 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-28543 | Crítica (9.8) | 0.36% | — | 5 sept 2023 | A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source). |
| CVE-2023-21664 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory Corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-21662 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-28537 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. |
| CVE-2023-22666 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21651 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2023-21670 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2022-33273 | Media (5.5) | 0.12% | — | 2 may 2023 | Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-40503 | Alta (7.5) | 0.41% | — | 13 abr 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33296 | Alta (7.8) | 0.11% | — | 13 abr 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-33288 | Alta (8.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. |
| CVE-2022-33269 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. |
| CVE-2022-33231 | Alta (7.8) | 0.08% | — | 13 abr 2023 | Memory corruption due to double free in core while initializing the encryption key. |
| CVE-2022-40537 | Crítica (9.8) | 0.36% | — | 10 mar 2023 | Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40515 | Crítica (9.8) | 0.33% | — | 10 mar 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.