« Volver al listado

Qualcomm

Qualcomm Qcs9100 Firmware: vulnerabilidades y CVE

Qualcomm Qcs9100 Firmware tiene 75 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE75
Últimos 12 meses17
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47366Alta (7.8)0.10%—2 feb 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47369Media (5.5)0.08%—7 ene 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345Alta (8.4)0.08%—7 ene 2026
Cryptographic issue may occur while encrypting license data.
CVE-2025-47344Media (6.4)0.06%—7 ene 2026
Memory corruption while handling sensor utility operations.
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47337Media (6.7)0.08%—7 ene 2026
Memory corruption while accessing a synchronization object during concurrent operations.
CVE-2025-47335Media (6.7)0.08%—7 ene 2026
Memory corruption while parsing clock configuration data for a specific hardware type.
CVE-2025-47334Media (6.7)0.08%—7 ene 2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47370Media (6.5)0.12%—4 nov 2025
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
CVE-2025-47357Alta (7.8)0.07%—4 nov 2025
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
CVE-2025-27070Alta (7.8)0.06%—4 nov 2025
Memory corruption while performing encryption and decryption commands.
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27032Alta (7.8)0.08%—24 sept 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21481Alta (7.8)0.07%—24 sept 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21476Alta (7.8)0.09%—24 sept 2025
Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
CVE-2025-27033Media (6.1)0.08%—24 sept 2025
Information disclosure while running video usecase having rogue firmware.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27057Alta (7.5)0.23%—8 jul 2025
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2025-27052Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing data packets in diag received from Unix clients.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation38
  2. T1059 Command and Scripting Interpreter34
  3. T1190 Exploit Public-Facing Application20
  4. T1005 Data from Local System8
  5. T1499.004 Application or System Exploitation6
  6. T1499 Endpoint Denial of Service4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm