Qualcomm
Qualcomm Sdx65 Firmware: vulnerabilidades y CVE
Qualcomm Sdx65 Firmware tiene 184 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 17 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE184
Últimos 12 meses0
Críticas17
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22071 | Alta (7.8) | 0.46% | ⚠ Explotación activa | 14 jun 2022 | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-21664 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory Corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-21662 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in Core Platform while printing the response buffer in log. |
| CVE-2023-21653 | Alta (7.5) | 0.38% | — | 5 sept 2023 | Transient DOS in Modem while processing RRC reconfiguration message. |
| CVE-2023-21646 | Alta (7.5) | 0.38% | — | 5 sept 2023 | Transient DOS in Modem while processing invalid System Information Block 1. |
| CVE-2023-22666 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21652 | Alta (7.1) | 0.10% | — | 8 ago 2023 | Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use. |
| CVE-2023-21651 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40535 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to buffer over-read in WLAN while sending a packet to device. |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-40530 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. |
| CVE-2022-40527 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. |
| CVE-2022-33309 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes. |
| CVE-2022-33278 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity. |
| CVE-2022-33272 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS in modem due to reachable assertion. |
| CVE-2022-33257 | Alta (7) | 0.09% | — | 10 mar 2023 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. |
| CVE-2022-33256 | Crítica (9.8) | 0.53% | — | 10 mar 2023 | Memory corruption due to improper validation of array index in Multi-mode call processor. |
| CVE-2022-33254 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to reachable assertion in Modem while processing SIB1 Message. |
| CVE-2022-33250 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover. |
| CVE-2022-33244 | Alta (7.5) | 0.41% | — | 10 mar 2023 | Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
| CVE-2022-25709 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in modem due to use of out of range pointer offset while processing qmi msg |
| CVE-2022-25705 | Alta (7.8) | 0.13% | — | 10 mar 2023 | Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
| CVE-2022-25694 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
| CVE-2022-22075 | Media (5.5) | 0.12% | — | 10 mar 2023 | Information Disclosure in Graphics during GPU context switch. |
| CVE-2022-40514 | Crítica (9.8) | 0.47% | — | 12 feb 2023 | Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. |
| CVE-2022-40512 | Alta (7.5) | 0.42% | — | 12 feb 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
| CVE-2022-33306 | Alta (7.5) | 0.42% | — | 12 feb 2023 | Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs. |
| CVE-2022-33280 | Alta (8.8) | 0.33% | — | 12 feb 2023 | Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.