« Volver al listado

Qualcomm

Qualcomm Snapdragon 855 Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 855 Firmware tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-21424Alta (7.8)0.12%—3 mar 2025
Memory corruption while calling the NPU driver APIs concurrently.
CVE-2024-53014Alta (7.8)0.12%—3 mar 2025
Memory corruption may occur while validating ports and channels in Audio driver.
CVE-2024-43056Media (6.5)0.11%—3 mar 2025
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2024-43051Media (5.5)0.11%—3 mar 2025
Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33042Alta (7.8)0.13%—2 sept 2024
Memory corruption when Alternative Frequency offset value is set to 255.
CVE-2024-23357Media (5.5)0.09%—5 ago 2024
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2023-33021Alta (7.8)0.12%—5 sept 2023
Memory corruption in Graphics while processing user packets for command submission.
CVE-2023-28584Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
CVE-2023-28567Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command through WMI interfaces.
CVE-2023-28565Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
CVE-2023-28564Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
CVE-2023-28562Crítica (9.8)0.43%—5 sept 2023
Memory corruption while handling payloads from remote ESL.
CVE-2023-28575Alta (7.8)0.12%—8 ago 2023
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
CVE-2023-28542Alta (7.8)0.12%—4 jul 2023
Memory Corruption in WLAN HOST while fetching TX status information.
CVE-2023-28541Alta (7.8)0.12%—4 jul 2023
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
CVE-2023-22667Alta (7.8)0.12%—4 jul 2023
Memory Corruption in Audio while allocating the ion buffer during the music playback.
CVE-2023-22387Alta (7.8)0.12%—4 jul 2023
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
CVE-2023-21639Alta (7.8)0.11%—4 jul 2023
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
CVE-2023-21638Alta (7.8)0.11%—4 jul 2023
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
CVE-2023-21637Alta (7.8)0.11%—4 jul 2023
Memory corruption in Linux while calling system configuration APIs.
CVE-2023-21635Alta (7.8)0.11%—4 jul 2023
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
CVE-2023-21633Alta (7.8)0.11%—4 jul 2023
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
CVE-2023-21631Crítica (9.8)0.36%—4 jul 2023
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
CVE-2023-21629Media (6.8)0.19%—4 jul 2023
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1068 Exploitation for Privilege Escalation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm