« Volver al listado

Qualcomm

Qualcomm Sm4375 Firmware: vulnerabilidades y CVE

Qualcomm Sm4375 Firmware tiene 84 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE84
Últimos 12 meses0
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33079Alta (7.8)0.16%—5 dic 2023
Memory corruption in Audio while running invalid audio recording from ADSP.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33054Crítica (9.1)0.36%—5 dic 2023
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
CVE-2023-33044Alta (7.5)0.52%—5 dic 2023
Transient DOS in Data modem while handling TLB control messages from the Network.
CVE-2023-33043Alta (7.5)0.52%—5 dic 2023
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
CVE-2023-33042Alta (7.5)0.61%—5 dic 2023
Transient DOS in Modem after RRC Setup message is received.
CVE-2023-33022Alta (7.8)0.16%—5 dic 2023
Memory corruption in HLOS while invoking IOCTL calls from user-space.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33055Alta (7.8)0.14%—7 nov 2023
Memory Corruption in Audio while invoking callback function in driver from ADSP.
CVE-2023-33035Alta (7.8)0.11%—3 oct 2023
Memory corruption while invoking callback function of AFE from ADSP.
CVE-2023-33034Alta (7.8)0.11%—3 oct 2023
Memory corruption while parsing the ADSP response command.
CVE-2023-33029Alta (7.8)0.11%—3 oct 2023
Memory corruption in DSP Service during a remote call from HLOS to DSP.
CVE-2023-33027Alta (7.5)0.32%—3 oct 2023
Transient DOS in WLAN Firmware while parsing rsn ies.
CVE-2023-28540Alta (7.5)0.43%—3 oct 2023
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2023-21646Alta (7.5)0.38%—5 sept 2023
Transient DOS in Modem while processing invalid System Information Block 1.
CVE-2023-21644Alta (7.8)0.11%—5 sept 2023
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
CVE-2023-21636Alta (7.8)0.11%—5 sept 2023
Memory Corruption due to improper validation of array index in Linux while updating adn record.
CVE-2022-33275Alta (7.8)0.12%—5 sept 2023
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-28537Alta (7.8)0.12%—8 ago 2023
Memory corruption while allocating memory in COmxApeDec module in Audio.
CVE-2023-22666Alta (7.8)0.12%—8 ago 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21652Alta (7.1)0.10%—8 ago 2023
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
CVE-2023-21651Alta (7.8)0.12%—8 ago 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
CVE-2023-21649Alta (7.8)0.11%—8 ago 2023
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
CVE-2023-21626Alta (7.1)0.11%—8 ago 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Crítica (9.8)0.43%—8 ago 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2023-21670Alta (7.8)0.12%—6 jun 2023
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm