« Volver al listado

Qualcomm

Qualcomm Sm7125 Firmware: vulnerabilidades y CVE

Qualcomm Sm7125 Firmware tiene 47 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE47
Últimos 12 meses0
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33022Alta (7.8)0.16%—5 dic 2023
Memory corruption in HLOS while invoking IOCTL calls from user-space.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33027Alta (7.5)0.32%—3 oct 2023
Transient DOS in WLAN Firmware while parsing rsn ies.
CVE-2023-28540Alta (7.5)0.43%—3 oct 2023
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
CVE-2022-33275Alta (7.8)0.12%—5 sept 2023
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
CVE-2023-21670Alta (7.8)0.12%—6 jun 2023
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
CVE-2023-21669Alta (7.5)0.35%—6 jun 2023
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
CVE-2023-21659Alta (7.5)0.38%—6 jun 2023
Transient DOS in WLAN Firmware while processing frames with missing header fields.
CVE-2023-21628Alta (7.8)0.12%—6 jun 2023
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2022-40533Media (5.5)0.10%—6 jun 2023
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
CVE-2022-40529Alta (7.8)0.10%—6 jun 2023
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
CVE-2022-40523Media (5.5)0.11%—6 jun 2023
Information disclosure in Kernel due to indirect branch misprediction.
CVE-2022-40521Alta (7.5)0.35%—6 jun 2023
Transient DOS due to improper authorization in Modem
CVE-2022-40507Alta (7.8)1.3%—6 jun 2023
Memory corruption due to double free in Core while mapping HLOS address to the list.
CVE-2022-33264Alta (7.8)0.11%—6 jun 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
CVE-2022-22076Media (5.5)0.11%—6 jun 2023
information disclosure due to cryptographic issue in Core during RPMB read request.
CVE-2022-40504Alta (7.5)0.38%—2 may 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
CVE-2023-21666Alta (7.8)0.18%—2 may 2023
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665Alta (7.8)0.18%—2 may 2023
Memory corruption in Graphics while importing a file.
CVE-2022-40532Alta (7.8)0.12%—13 abr 2023
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
CVE-2022-40503Alta (7.5)0.41%—13 abr 2023
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
CVE-2022-33302Alta (7.8)0.12%—13 abr 2023
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
CVE-2022-33298Alta (7.8)0.11%—13 abr 2023
Memory corruption due to use after free in Modem while modem initialization.
CVE-2022-33296Alta (7.8)0.11%—13 abr 2023
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
CVE-2022-33289Media (6.8)0.19%—13 abr 2023
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm