Qualcomm
Qualcomm Sm7125 Firmware: vulnerabilidades y CVE
Qualcomm Sm7125 Firmware tiene 47 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE47
Últimos 12 meses0
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33063 | Alta (7.8) | 0.69% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33080 | Alta (7.5) | 0.34% | — | 5 dic 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33063 | Alta (7.8) | 0.69% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33022 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-33017 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-33027 | Alta (7.5) | 0.32% | — | 3 oct 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. |
| CVE-2023-28540 | Alta (7.5) | 0.43% | — | 3 oct 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2022-33275 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. |
| CVE-2023-21670 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. |
| CVE-2023-21669 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address. |
| CVE-2023-21659 | Alta (7.5) | 0.38% | — | 6 jun 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. |
| CVE-2023-21628 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-40533 | Media (5.5) | 0.10% | — | 6 jun 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. |
| CVE-2022-40529 | Alta (7.8) | 0.10% | — | 6 jun 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. |
| CVE-2022-40523 | Media (5.5) | 0.11% | — | 6 jun 2023 | Information disclosure in Kernel due to indirect branch misprediction. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-40507 | Alta (7.8) | 1.3% | — | 6 jun 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-40503 | Alta (7.5) | 0.41% | — | 13 abr 2023 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33298 | Alta (7.8) | 0.11% | — | 13 abr 2023 | Memory corruption due to use after free in Modem while modem initialization. |
| CVE-2022-33296 | Alta (7.8) | 0.11% | — | 13 abr 2023 | Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.