« Volver al listado

Qualcomm

Qualcomm Sm6225 Firmware: vulnerabilidades y CVE

Qualcomm Sm6225 Firmware tiene 92 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE92
Últimos 12 meses0
Críticas7
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-30299Media (6.7)0.12%—22 nov 2024
Possible out of bound access in audio module due to lack of validation of user provided input.
CVE-2023-33087Alta (7.8)0.16%—5 dic 2023
Memory corruption in Core while processing RX intent request.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33079Alta (7.8)0.16%—5 dic 2023
Memory corruption in Audio while running invalid audio recording from ADSP.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33054Crítica (9.1)0.36%—5 dic 2023
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
CVE-2023-33022Alta (7.8)0.16%—5 dic 2023
Memory corruption in HLOS while invoking IOCTL calls from user-space.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-33074Alta (7.8)0.14%—7 nov 2023
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33055Alta (7.8)0.14%—7 nov 2023
Memory Corruption in Audio while invoking callback function in driver from ADSP.
CVE-2023-33031Alta (7.8)0.11%—7 nov 2023
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
CVE-2023-33035Alta (7.8)0.11%—3 oct 2023
Memory corruption while invoking callback function of AFE from ADSP.
CVE-2023-33029Alta (7.8)0.11%—3 oct 2023
Memory corruption in DSP Service during a remote call from HLOS to DSP.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2022-33275Alta (7.8)0.12%—5 sept 2023
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-28555Alta (7.5)0.41%—8 ago 2023
Transient DOS in Audio while remapping channel buffer in media codec decoding.
CVE-2023-21659Alta (7.5)0.38%—6 jun 2023
Transient DOS in WLAN Firmware while processing frames with missing header fields.
CVE-2023-21657Alta (7.8)0.12%—6 jun 2023
Memoru corruption in Audio when ADSP sends input during record use case.
CVE-2023-21656Alta (7.8)0.12%—6 jun 2023
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
CVE-2023-21628Alta (7.8)0.12%—6 jun 2023
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2022-40533Media (5.5)0.10%—6 jun 2023
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
CVE-2022-40529Alta (7.8)0.10%—6 jun 2023
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
CVE-2022-40523Media (5.5)0.11%—6 jun 2023
Information disclosure in Kernel due to indirect branch misprediction.
CVE-2022-40521Alta (7.5)0.35%—6 jun 2023
Transient DOS due to improper authorization in Modem
CVE-2022-40507Alta (7.8)1.3%—6 jun 2023
Memory corruption due to double free in Core while mapping HLOS address to the list.
CVE-2022-33264Alta (7.8)0.11%—6 jun 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-22076Media (5.5)0.11%—6 jun 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40504Alta (7.5)0.38%—2 may 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm