Qualcomm
Qualcomm Qsm8250 Firmware: vulnerabilidades y CVE
Qualcomm Qsm8250 Firmware tiene 216 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 10 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE216
Últimos 12 meses2
Críticas10
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33063 | Alta (7.8) | 0.57% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33107 | Alta (7.8) | 0.72% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27054 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption while processing a malformed license file during reboot. |
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-21481 | Alta (7.8) | 0.07% | — | 24 sept 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-27030 | Media (6.1) | 0.08% | — | 24 sept 2025 | information disclosure while invoking calibration data from user space to update firmware size. |
| CVE-2025-27071 | Crítica (9.8) | 0.18% | — | 6 ago 2025 | Memory corruption while processing specific files in Powerline Communication Firmware. |
| CVE-2025-27066 | Alta (7.5) | 0.28% | — | 6 ago 2025 | Transient DOS while processing an ANQP message. |
| CVE-2025-21465 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2025-21455 | Alta (7.8) | 0.07% | — | 6 ago 2025 | Memory corruption while submitting blob data to kernel space though IOCTL. |
| CVE-2025-27061 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| CVE-2025-27042 | Alta (7.8) | 0.09% | — | 8 jul 2025 | Memory corruption while processing video packets received from video firmware. |
| CVE-2024-53016 | Media (6.6) | 0.08% | — | 3 jun 2025 | Memory corruption while processing I2C settings in Camera driver. |
| CVE-2024-53013 | Media (6.6) | 0.09% | — | 3 jun 2025 | Memory corruption may occur while processing voice call registration with user. |
| CVE-2024-49844 | Alta (7.8) | 0.11% | — | 6 may 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. |
| CVE-2024-45570 | Alta (7.8) | 0.11% | — | 6 may 2025 | Memory corruption may occur during IO configuration processing when the IO port count is invalid. |
| CVE-2024-45562 | Alta (7.8) | 0.11% | — | 6 may 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. |
| CVE-2025-21448 | Alta (7.5) | 0.26% | — | 7 abr 2025 | Transient DOS may occur while parsing SSID in action frames. |
| CVE-2024-45549 | Alta (7.7) | 0.12% | — | 7 abr 2025 | Information disclosure while creating MQ channels. |
| CVE-2024-45543 | Media (6.6) | 0.11% | — | 7 abr 2025 | Memory corruption while accessing MSM channel map and mixer functions. |
| CVE-2024-45540 | Media (6.6) | 0.11% | — | 7 abr 2025 | Memory corruption while invoking IOCTL map buffer request from userspace. |
| CVE-2024-43067 | Alta (7.8) | 0.09% | — | 7 abr 2025 | Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory. |
| CVE-2024-43046 | Media (5.5) | 0.11% | — | 7 abr 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2025-21424 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while calling the NPU driver APIs concurrently. |
| CVE-2024-53014 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption may occur while validating ports and channels in Audio driver. |
| CVE-2024-43057 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-43051 | Media (5.5) | 0.11% | — | 3 mar 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-38418 | Alta (7) | 0.07% | — | 3 feb 2025 | Memory corruption while parsing the memory map info in IOCTL calls. |
| CVE-2024-38416 | Media (5.5) | 0.10% | — | 3 feb 2025 | Information disclosure during audio playback. |
| CVE-2024-33067 | Media (5.5) | 0.10% | — | 6 ene 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
| CVE-2024-43052 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while processing API calls to NPU with invalid input. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.