Qualcomm
Qualcomm SD 8 Gen1 5G Firmware: vulnerabilidades y CVE
Qualcomm SD 8 Gen1 5G Firmware tiene 429 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 36 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE429
Últimos 12 meses24
Críticas36
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33106 | Alta (7.8) | 0.79% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. |
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24084 | Alta (7.5) | 0.25% | — | 4 ago 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. |
| CVE-2026-24079 | Alta (8.1) | 0.21% | — | 4 ago 2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. |
| CVE-2026-24078 | Media (6.5) | 0.17% | — | 4 ago 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. |
| CVE-2026-24077 | Media (6.5) | 0.17% | — | 4 ago 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. |
| CVE-2026-21384 | Media (5.3) | 0.08% | — | 6 jul 2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. |
| CVE-2026-21370 | Media (5.3) | 0.08% | — | 6 jul 2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. |
| CVE-2026-21368 | Media (5.3) | 0.08% | — | 6 jul 2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. |
| CVE-2026-24091 | Alta (7.2) | 0.10% | — | 1 jun 2026 | Memory corruption while processing fastboot commands with improperly formatted input. |
| CVE-2026-24088 | Alta (8.2) | 0.07% | — | 1 jun 2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. |
| CVE-2026-24085 | Alta (7.2) | 0.10% | — | 1 jun 2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. |
| CVE-2025-59610 | Media (6.4) | 0.06% | — | 1 jun 2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. |
| CVE-2025-59605 | Alta (7.8) | 0.07% | — | 1 jun 2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. |
| CVE-2025-59604 | Alta (7.8) | 0.07% | — | 1 jun 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
| CVE-2025-47403 | Alta (7.5) | 0.22% | — | 4 may 2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. |
| CVE-2026-21367 | Alta (7.5) | 0.20% | — | 6 abr 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
| CVE-2025-47392 | Alta (8.8) | 0.17% | — | 6 abr 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. |
| CVE-2025-47391 | Alta (7.8) | 0.10% | — | 6 abr 2026 | Memory corruption while processing a frame request from user. |
| CVE-2025-47397 | Alta (7.8) | 0.11% | — | 2 feb 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. |
| CVE-2025-47366 | Alta (7.8) | 0.10% | — | 2 feb 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. |
| CVE-2025-47369 | Media (5.5) | 0.08% | — | 7 ene 2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. |
| CVE-2025-47334 | Media (6.7) | 0.08% | — | 7 ene 2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. |
| CVE-2025-27070 | Alta (7.8) | 0.06% | — | 4 nov 2025 | Memory corruption while performing encryption and decryption commands. |
| CVE-2025-27054 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption while processing a malformed license file during reboot. |
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-47318 | Alta (7.5) | 0.21% | — | 24 sept 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-27034 | Crítica (9.8) | 0.40% | — | 24 sept 2025 | Memory corruption while selecting the PLMN from SOR failed list. |
| CVE-2025-27032 | Alta (7.8) | 0.08% | — | 24 sept 2025 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency. |
| CVE-2025-21483 | Crítica (9.8) | 0.40% | — | 24 sept 2025 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. |
| CVE-2025-21481 | Alta (7.8) | 0.07% | — | 24 sept 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-21488 | Alta (8.2) | 0.27% | — | 24 sept 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.