Qualcomm
Qualcomm SD 427 Firmware: vulnerabilidades y CVE
Qualcomm SD 427 Firmware tiene 174 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 52 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE174
Últimos 12 meses0
Críticas52
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-11922 | Media (5.5) | 0.23% | — | 26 nov 2024 | Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| CVE-2017-11076 | Crítica (9.8) | 0.35% | — | 26 nov 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2019-2332 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-2331 | Crítica (9.8) | 1.2% | — | 6 nov 2019 | Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2325 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2324 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary access in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-2323 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-2285 | Crítica (9.8) | 1.1% | — | 6 nov 2019 | Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-2283 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-2275 | Media (5.5) | 0.19% | — | 6 nov 2019 | While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key operations are invoked(Depends on CVE-2018-13907) in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-2258 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2019-2249 | Crítica (9.8) | 1.4% | — | 6 nov 2019 | Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-2246 | Alta (7.8) | 0.20% | — | 6 nov 2019 | Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-10542 | Crítica (9.8) | 0.71% | — | 6 nov 2019 | Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon… |
| CVE-2019-10534 | Crítica (9.8) | 1.1% | — | 6 nov 2019 | Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-10533 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-10528 | Crítica (9.8) | 0.71% | — | 6 nov 2019 | Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-10524 | Alta (7.8) | 0.19% | — | 6 nov 2019 | Lack of check for a negative value returned for get_clk is wrongly interpreted as valid pointer and lead to use after free in clk driver in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-10522 | Crítica (9.8) | 0.71% | — | 6 nov 2019 | While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-10515 | Media (5.5) | 0.17% | — | 6 nov 2019 | DCI client which might be preemptively freed up might be accessed for transferring packets leading to kernel error in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-10512 | Alta (7.8) | 0.19% | — | 6 nov 2019 | Payload size is not checked before using it as array index in audio in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… |
| CVE-2019-10504 | Media (6.5) | 0.55% | — | 6 nov 2019 | Firmware not able to send EXT scan response to host within 1 sec due to resource consumption issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-10496 | Alta (7.8) | 0.19% | — | 6 nov 2019 | Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2019-10495 | Alta (7.3) | 0.19% | — | 6 nov 2019 | Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-10491 | Alta (7.8) | 0.19% | — | 6 nov 2019 | ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-10488 | Alta (7.5) | 0.81% | — | 6 nov 2019 | Null pointer dereference can occur while parsing invalid chunks while playing the nonstandard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2019-2341 | Alta (7.8) | 0.19% | — | 30 sept 2019 | Buffer overflow when the audio buffer size provided by user is larger than the maximum allowable audio buffer size. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2333 | Alta (7.8) | 0.19% | — | 30 sept 2019 | Buffer overflow due to improper validation of buffer size while IPA driver processing to perform read operation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2294 | Crítica (9.8) | 0.91% | — | 30 sept 2019 | Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-2252 | Crítica (9.8) | 1.2% | — | 30 sept 2019 | Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.