Qualcomm
Qualcomm Sc8180x Firmware: vulnerabilidades y CVE
Qualcomm Sc8180x Firmware tiene 220 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 80 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE220
Últimos 12 meses0
Críticas80
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-43050 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33044 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while Configuring the SMR/S2CR register in Bypass mode. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2022-40514 | Crítica (9.8) | 0.47% | — | 12 feb 2023 | Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. |
| CVE-2022-40512 | Alta (7.5) | 0.42% | — | 12 feb 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
| CVE-2022-33277 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. |
| CVE-2022-33271 | Alta (7.5) | 0.38% | — | 12 feb 2023 | Information disclosure due to buffer over-read in WLAN while parsing NMF frame. |
| CVE-2022-33248 | Alta (7.8) | 0.13% | — | 12 feb 2023 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. |
| CVE-2022-33233 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-40520 | Alta (7.8) | 0.70% | — | 9 ene 2023 | Memory corruption due to stack-based buffer overflow in Core |
| CVE-2022-40519 | Media (5.5) | 0.11% | — | 9 ene 2023 | Information disclosure due to buffer overread in Core |
| CVE-2022-40518 | Media (5.5) | 0.11% | — | 9 ene 2023 | Information disclosure due to buffer overread in Core |
| CVE-2022-40517 | Alta (7.8) | 0.14% | — | 9 ene 2023 | Memory corruption in core due to stack-based buffer overflow |
| CVE-2022-40516 | Alta (7.8) | 0.87% | — | 9 ene 2023 | Memory corruption in Core due to stack-based buffer overflow. |
| CVE-2022-33286 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. |
| CVE-2022-33285 | Media (6.5) | 0.38% | — | 9 ene 2023 | Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
| CVE-2022-33284 | Media (6.5) | 0.35% | — | 9 ene 2023 | Information disclosure due to buffer over-read in WLAN while parsing BTM action frame. |
| CVE-2021-30327 | Media (6.8) | 0.20% | — | 14 jun 2022 | Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon… |
| CVE-2021-1920 | Crítica (9.8) | 0.80% | — | 8 sept 2021 | Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… |
| CVE-2021-1919 | Crítica (9.8) | 0.80% | — | 8 sept 2021 | Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1916 | Crítica (9.8) | 0.80% | — | 8 sept 2021 | Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2021-1914 | Alta (7.5) | 0.59% | — | 8 sept 2021 | Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2020-11301 | Alta (7.5) | 11% | — | 8 sept 2021 | Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2021-1896 | Media (4.3) | 0.17% | — | 13 jul 2021 | Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity |
| CVE-2020-11176 | Crítica (9.8) | 0.68% | — | 9 jun 2021 | While processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow which can lead to memory corruption in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2020-11255 | Alta (7.5) | 0.71% | — | 7 abr 2021 | Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon… |
| CVE-2020-11252 | Media (5.5) | 0.19% | — | 7 abr 2021 | Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2020-11251 | Crítica (9.1) | 0.94% | — | 7 abr 2021 | Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2020-11227 | Crítica (9.8) | 0.91% | — | 17 mar 2021 | Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.