Qualcomm
Qualcomm Snapdragon 855 Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon 855 Firmware tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21424 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while calling the NPU driver APIs concurrently. |
| CVE-2024-53014 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption may occur while validating ports and channels in Audio driver. |
| CVE-2024-43056 | Media (6.5) | 0.11% | — | 3 mar 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| CVE-2024-43051 | Media (5.5) | 0.11% | — | 3 mar 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33042 | Alta (7.8) | 0.13% | — | 2 sept 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-23357 | Media (5.5) | 0.09% | — | 5 ago 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| CVE-2023-33021 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in Graphics while processing user packets for command submission. |
| CVE-2023-28584 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). |
| CVE-2023-28567 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command through WMI interfaces. |
| CVE-2023-28565 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
| CVE-2023-28564 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
| CVE-2023-28562 | Crítica (9.8) | 0.43% | — | 5 sept 2023 | Memory corruption while handling payloads from remote ESL. |
| CVE-2023-28575 | Alta (7.8) | 0.12% | — | 8 ago 2023 | The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. |
| CVE-2023-28542 | Alta (7.8) | 0.12% | — | 4 jul 2023 | Memory Corruption in WLAN HOST while fetching TX status information. |
| CVE-2023-28541 | Alta (7.8) | 0.12% | — | 4 jul 2023 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. |
| CVE-2023-22667 | Alta (7.8) | 0.12% | — | 4 jul 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| CVE-2023-22387 | Alta (7.8) | 0.12% | — | 4 jul 2023 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
| CVE-2023-21639 | Alta (7.8) | 0.11% | — | 4 jul 2023 | Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client. |
| CVE-2023-21638 | Alta (7.8) | 0.11% | — | 4 jul 2023 | Memory corruption in Video while calling APIs with different instance ID than the one received in initialization. |
| CVE-2023-21637 | Alta (7.8) | 0.11% | — | 4 jul 2023 | Memory corruption in Linux while calling system configuration APIs. |
| CVE-2023-21635 | Alta (7.8) | 0.11% | — | 4 jul 2023 | Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. |
| CVE-2023-21633 | Alta (7.8) | 0.11% | — | 4 jul 2023 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. |
| CVE-2023-21631 | Crítica (9.8) | 0.36% | — | 4 jul 2023 | Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| CVE-2023-21629 | Media (6.8) | 0.19% | — | 4 jul 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.