« Volver al listado

Qualcomm

Qualcomm Snapdragon 660 Mobile Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 660 Mobile Firmware tiene 25 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses2
Críticas1
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47398Alta (7.8)0.11%—2 feb 2026
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21427Alta (8.2)0.22%—8 jul 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21467Alta (7.8)0.11%—6 may 2025
Memory corruption while reading the FW response from the shared queue.
CVE-2025-21453Alta (7.8)0.11%—6 may 2025
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.
CVE-2024-33060Alta (7.8)0.17%—2 sept 2024
Memory corruption when two threads try to map and unmap a single node simultaneously.
CVE-2024-33052Alta (7.8)0.13%—2 sept 2024
Memory corruption when user provides data for FM HCI command control operations.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-43545Alta (7.8)0.10%—3 jun 2024
Memory corruption when more scan frequency list or channels are sent from the user space.
CVE-2024-21475Alta (7.8)0.11%—6 may 2024
Memory corruption when the payload received from firmware is not as per the expected protocol size.
CVE-2024-21471Alta (7.8)0.11%—6 may 2024
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
CVE-2023-43528Media (5.5)0.11%—6 may 2024
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
CVE-2023-43527Media (5.5)0.12%—6 may 2024
Information disclosure while parsing dts header atom in Video.
CVE-2024-21468Alta (7.8)0.11%—1 abr 2024
Memory corruption when there is failed unmap operation in GPU.
CVE-2023-33023Alta (7.8)0.11%—1 abr 2024
Memory corruption while processing finish_sign command to pass a rsp buffer.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-43548Crítica (9.8)0.26%—4 mar 2024
Memory corruption while parsing qcp clip with invalid chunk data size.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-28578Alta (7.8)0.12%—4 mar 2024
Memory corruption in Core Services while executing the command for removing a single event listener.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter8
  2. T1068 Exploitation for Privilege Escalation8
  3. T1190 Exploit Public-Facing Application3
  4. T1499.004 Application or System Exploitation2
  5. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm