« Volver al listado

Qualcomm

Qualcomm Sm8475p Firmware: vulnerabilidades y CVE

Qualcomm Sm8475p Firmware tiene 75 vulnerabilidades publicadas, 31 de ellas en los últimos 12 meses. 11 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE75
Últimos 12 meses31
Críticas11
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24084Alta (7.5)0.25%—4 ago 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24079Alta (8.1)0.21%—4 ago 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Media (6.5)0.17%—4 ago 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Media (6.5)0.17%—4 ago 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59605Alta (7.8)0.07%—1 jun 2026
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-47403Alta (7.5)0.22%—4 may 2026
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
CVE-2025-47401Alta (7.5)0.22%—4 may 2026
Transient DOS when processing target power rate tables during channel configuration.
CVE-2026-21367Alta (7.5)0.20%—6 abr 2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2025-47392Alta (8.8)0.17%—6 abr 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47391Alta (7.8)0.10%—6 abr 2026
Memory corruption while processing a frame request from user.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47373Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
CVE-2025-47371Media (6.5)0.11%—2 mar 2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
CVE-2025-47398Alta (7.8)0.11%—2 feb 2026
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
CVE-2025-47397Alta (7.8)0.11%—2 feb 2026
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
CVE-2025-47366Alta (7.8)0.10%—2 feb 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47369Media (5.5)0.08%—7 ene 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47334Media (6.7)0.08%—7 ene 2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47332Media (6.4)0.06%—7 ene 2026
Memory corruption while processing a config call from userspace.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter13
  2. T1068 Exploitation for Privilege Escalation11
  3. T1190 Exploit Public-Facing Application5
  4. T1210 Exploitation of Remote Services3
  5. T1499.004 Application or System Exploitation3
  6. T1091 Replication Through Removable Media2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm