« Volver al listado

Qualcomm

Qualcomm Sc8180x Firmware: vulnerabilidades y CVE

Qualcomm Sc8180x Firmware tiene 220 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 80 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE220
Últimos 12 meses0
Críticas80
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-43050Alta (7.8)0.10%—2 dic 2024
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044Alta (7.8)0.10%—2 dic 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2022-40514Crítica (9.8)0.47%—12 feb 2023
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
CVE-2022-40512Alta (7.5)0.42%—12 feb 2023
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
CVE-2022-33277Alta (7.8)0.12%—12 feb 2023
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
CVE-2022-33271Alta (7.5)0.38%—12 feb 2023
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
CVE-2022-33248Alta (7.8)0.13%—12 feb 2023
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
CVE-2022-33233Alta (7.8)0.12%—12 feb 2023
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
CVE-2022-40520Alta (7.8)0.70%—9 ene 2023
Memory corruption due to stack-based buffer overflow in Core
CVE-2022-40519Media (5.5)0.11%—9 ene 2023
Information disclosure due to buffer overread in Core
CVE-2022-40518Media (5.5)0.11%—9 ene 2023
Information disclosure due to buffer overread in Core
CVE-2022-40517Alta (7.8)0.14%—9 ene 2023
Memory corruption in core due to stack-based buffer overflow
CVE-2022-40516Alta (7.8)0.87%—9 ene 2023
Memory corruption in Core due to stack-based buffer overflow.
CVE-2022-33286Media (6.5)0.38%—9 ene 2023
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
CVE-2022-33285Media (6.5)0.38%—9 ene 2023
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
CVE-2022-33284Media (6.5)0.35%—9 ene 2023
Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.
CVE-2021-30327Media (6.8)0.20%—14 jun 2022
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon…
CVE-2021-1920Crítica (9.8)0.80%—8 sept 2021
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
CVE-2021-1919Crítica (9.8)0.80%—8 sept 2021
Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1916Crítica (9.8)0.80%—8 sept 2021
Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2021-1914Alta (7.5)0.59%—8 sept 2021
Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2020-11301Alta (7.5)11%—8 sept 2021
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…
CVE-2021-1896Media (4.3)0.17%—13 jul 2021
Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity
CVE-2020-11176Crítica (9.8)0.68%—9 jun 2021
While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute,…
CVE-2020-11255Alta (7.5)0.71%—7 abr 2021
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon…
CVE-2020-11252Media (5.5)0.19%—7 abr 2021
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2020-11251Crítica (9.1)0.94%—7 abr 2021
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
CVE-2020-11227Crítica (9.8)0.91%—17 mar 2021
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1059 Command and Scripting Interpreter2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm