Qualcomm
Qualcomm Qcs8155 Firmware: vulnerabilidades y CVE
Qualcomm Qcs8155 Firmware tiene 79 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE79
Últimos 12 meses1
Críticas0
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33063 | Alta (7.8) | 0.69% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33107 | Alta (7.8) | 0.89% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-27062 | Alta (7.8) | 0.08% | — | 6 ago 2025 | Memory corruption while handling client exceptions, allowing unauthorized channel access. |
| CVE-2025-21465 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2025-27061 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| CVE-2025-27042 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption while processing video packets received from video firmware. |
| CVE-2024-49844 | Alta (7.8) | 0.11% | — | 6 may 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. |
| CVE-2025-21424 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while calling the NPU driver APIs concurrently. |
| CVE-2024-53011 | Alta (7.9) | 0.12% | — | 3 mar 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33044 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-33016 | Media (6.8) | 0.15% | — | 2 sept 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-21469 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
| CVE-2024-21465 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while processing key blob passed by the user. |
| CVE-2024-21462 | Media (5.5) | 0.09% | — | 1 jul 2024 | Transient DOS while loading the TA ELF file. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-43542 | Alta (7.8) | 0.10% | — | 3 jun 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. |
| CVE-2024-21475 | Alta (7.8) | 0.11% | — | 6 may 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| CVE-2024-21468 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-28547 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption in SPS Application while requesting for public key in sorter TA. |
| CVE-2023-43513 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| CVE-2023-33077 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| CVE-2023-33032 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. |
| CVE-2023-33030 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in HLOS while running playready use-case. |
| CVE-2023-33107 | Alta (7.8) | 0.89% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2023-33070 | Media (5.5) | 0.14% | — | 5 dic 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. |
| CVE-2023-33063 | Alta (7.8) | 0.69% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33017 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| CVE-2023-28586 | Media (6.5) | 0.14% | — | 5 dic 2023 | Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.