« Volver al listado

Qualcomm

Qualcomm Snapdragon 7S GEN 3 Mobile Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 7S GEN 3 Mobile Platform Firmware tiene 33 vulnerabilidades publicadas, 33 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE33
Últimos 12 meses33
Críticas1
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24081Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-25289Crítica (9.6)0.19%—4 ago 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-24084Alta (7.5)0.25%—4 ago 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24079Alta (8.1)0.21%—4 ago 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Media (6.5)0.17%—4 ago 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Media (6.5)0.17%—4 ago 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24092Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090Alta (7.1)0.06%—1 jun 2026
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
CVE-2026-24089Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-24087Alta (7.2)0.10%—1 jun 2026
Memory corruption while processing fastboot OEM commands.
CVE-2026-24085Alta (7.2)0.10%—1 jun 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Media (6.4)0.06%—1 jun 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59609Media (5.5)0.09%—1 jun 2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2026-21381Alta (7.5)0.15%—6 abr 2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
CVE-2026-21367Alta (7.5)0.20%—6 abr 2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2025-47392Alta (8.8)0.17%—6 abr 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47391Alta (7.8)0.10%—6 abr 2026
Memory corruption while processing a frame request from user.
CVE-2025-47389Alta (7.8)0.10%—6 abr 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-59600Alta (7.8)0.07%—2 mar 2026
Memory Corruption when adding user-supplied data without checking available buffer space.
CVE-2025-47386Alta (7.8)0.07%—2 mar 2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47385Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing trusted execution environment without proper privilege check.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47379Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
CVE-2025-47377Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
CVE-2025-47376Alta (7.8)0.07%—2 mar 2026
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter17
  2. T1068 Exploitation for Privilege Escalation16
  3. T1091 Replication Through Removable Media5
  4. T1210 Exploitation of Remote Services5
  5. T1190 Exploit Public-Facing Application4
  6. T1499.004 Application or System Exploitation3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm