Qualcomm
Qualcomm Sdm429 Firmware: vulnerabilidades y CVE
Qualcomm Sdm429 Firmware tiene 211 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 75 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE211
Últimos 12 meses0
Críticas75
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-11076 | Crítica (9.8) | 0.35% | — | 26 nov 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-33031 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. |
| CVE-2023-21670 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. |
| CVE-2023-21669 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address. |
| CVE-2023-21659 | Alta (7.5) | 0.38% | — | 6 jun 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. |
| CVE-2023-21658 | Alta (7.5) | 0.38% | — | 6 jun 2023 | Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. |
| CVE-2023-21657 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memoru corruption in Audio when ADSP sends input during record use case. |
| CVE-2023-21656 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33267 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in Linux while sending DRM request. |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-33227 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-40503 | Alta (7.5) | 0.41% | — | 13 abr 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33296 | Alta (7.8) | 0.11% | — | 13 abr 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2020-3639 | Crítica (9.8) | 0.91% | — | 12 nov 2020 | u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2020-11196 | Crítica (9.8) | 0.90% | — | 12 nov 2020 | u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2020-11193 | Crítica (9.8) | 0.91% | — | 12 nov 2020 | u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2020-11168 | Crítica (9.8) | 0.91% | — | 12 nov 2020 | u'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial… |
| CVE-2020-11123 | Media (5.5) | 0.19% | — | 12 nov 2020 | u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper… |
| CVE-2020-3703 | Crítica (9.8) | 0.71% | — | 2 nov 2020 | u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(This CVE is equivalent to Link Layer Length Overfow issue… |
| CVE-2020-3673 | Crítica (9.8) | 1.1% | — | 2 nov 2020 | u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2020-3670 | Crítica (9.1) | 0.88% | — | 2 nov 2020 | u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Information Element(IEI) NAS message container' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.