« Volver al listado

Qualcomm

Qualcomm Snapdragon 660 Mobile Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 660 Mobile Platform Firmware tiene 84 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 5 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE84
Últimos 12 meses17
Críticas5
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2023-33106Alta (7.8)0.75%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.72%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47386Alta (7.8)0.07%—2 mar 2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47379Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
CVE-2025-47376Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
CVE-2025-47375Alta (7.8)0.07%—2 mar 2026
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
CVE-2025-47369Media (5.5)0.08%—7 ene 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47320Alta (7.8)0.08%—18 dic 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27063Alta (7.8)0.10%—18 dic 2025
Memory corruption during video playback when video session open fails with time out error.
CVE-2025-27041Media (5.5)0.08%—9 oct 2025
Transient DOS while processing video packets received from video firmware.
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21488Alta (8.2)0.27%—24 sept 2025
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-27062Alta (7.8)0.08%—6 ago 2025
Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2025-21430Alta (7.5)0.26%—7 abr 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2025-21429Alta (7.5)0.26%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2024-45552Alta (8.2)0.26%—7 abr 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-43066Alta (7.8)0.11%—7 abr 2025
Memory corruption while handling file descriptor during listener registration/de-registration.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter15
  2. T1068 Exploitation for Privilege Escalation15
  3. T1190 Exploit Public-Facing Application12
  4. T1005 Data from Local System7
  5. T1499 Endpoint Denial of Service3
  6. T1091 Replication Through Removable Media2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm