« Volver al listado

Qualcomm

Qualcomm Sa8145p Firmware: vulnerabilidades y CVE

Qualcomm Sa8145p Firmware tiene 540 vulnerabilidades publicadas, 43 de ellas en los últimos 12 meses. 33 son críticas y 5 figuran en el catálogo de explotación activa de CISA.

CVE540
Últimos 12 meses43
Críticas33
Explotadas activamente5

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33106Alta (7.8)0.92%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.89%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25292Alta (7.6)0.15%—4 ago 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-24080Alta (7.8)0.10%—4 ago 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-21366Alta (7.8)0.10%—4 ago 2026
Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59606Alta (7.8)0.07%—1 jun 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59605Alta (7.8)0.07%—1 jun 2026
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2026-24082Alta (7.8)0.07%—4 may 2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47389Alta (7.8)0.10%—6 abr 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-59600Alta (7.8)0.07%—2 mar 2026
Memory Corruption when adding user-supplied data without checking available buffer space.
CVE-2025-47386Alta (7.8)0.07%—2 mar 2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47379Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
CVE-2025-47376Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
CVE-2025-47375Alta (7.8)0.07%—2 mar 2026
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
CVE-2025-47373Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
CVE-2025-47366Alta (7.8)0.10%—2 feb 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47364Alta (7.8)0.10%—2 feb 2026
Memory corruption while calculating offset from partition start point.
CVE-2025-47363Alta (7.8)0.10%—2 feb 2026
Memory corruption when calculating oversized partition sizes without proper checks.
CVE-2025-47369Media (5.5)0.08%—7 ene 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation81
  2. T1059 Command and Scripting Interpreter78
  3. T1190 Exploit Public-Facing Application19
  4. T1005 Data from Local System9
  5. T1499.004 Application or System Exploitation7
  6. T1091 Replication Through Removable Media3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm