Qualcomm
Qualcomm Sda429w Firmware: vulnerabilidades y CVE
Qualcomm Sda429w Firmware tiene 169 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 29 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE169
Últimos 12 meses0
Críticas29
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-30299 | Media (6.7) | 0.12% | — | 22 nov 2024 | Possible out of bound access in audio module due to lack of validation of user provided input. |
| CVE-2023-21663 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory Corruption while accessing metadata in Display. |
| CVE-2023-21655 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory corruption in Audio while validating and mapping metadata. |
| CVE-2023-21654 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory corruption in Audio during playback session with audio effects enabled. |
| CVE-2023-21644 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request. |
| CVE-2023-21636 | Alta (7.8) | 0.11% | — | 5 sept 2023 | Memory Corruption due to improper validation of array index in Linux while updating adn record. |
| CVE-2023-22666 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21650 | Alta (7.8) | 0.11% | — | 8 ago 2023 | Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length. |
| CVE-2023-21649 | Alta (7.8) | 0.11% | — | 8 ago 2023 | Memory corruption in WLAN while running doDriverCmd for an unspecific command. |
| CVE-2023-21648 | Alta (7.8) | 0.11% | — | 8 ago 2023 | Memory corruption in RIL while trying to send apdu packet. |
| CVE-2023-21627 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory corruption in Trusted Execution Environment while calling service API with invalid address. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40515 | Crítica (9.8) | 0.33% | — | 10 mar 2023 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. |
| CVE-2022-33260 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption due to stack based buffer overflow in core while sending command from USB of large size. |
| CVE-2022-33242 | Alta (7.8) | 0.14% | — | 10 mar 2023 | Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25705 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-22075 | Media (5.5) | 0.12% | — | 10 mar 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-33248 | Alta (7.8) | 0.13% | — | 12 feb 2023 | Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. |
| CVE-2022-33246 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id. |
| CVE-2022-33233 | Alta (7.8) | 0.12% | — | 12 feb 2023 | Memory corruption due to configuration weakness in modem wile sending command to write protected files. |
| CVE-2022-33266 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
| CVE-2022-25721 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in video driver due to type confusion error during video playback |
| CVE-2022-25717 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in display due to double free while allocating frame buffer memory |
| CVE-2022-25715 | Alta (7.8) | 0.11% | — | 9 ene 2023 | Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields |
| CVE-2022-22079 | Media (4.6) | 0.17% | — | 9 ene 2023 | Denial of service while processing fastboot flash command on mmc due to buffer over read |
| CVE-2022-25712 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables |
| CVE-2022-25711 | Alta (7.8) | 0.13% | — | 13 dic 2022 | Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.