« Volver al listado

Qualcomm

Qualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 8CX GEN 3 Compute Platform Firmware tiene 48 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE48
Últimos 12 meses19
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25261Alta (7.8)0.07%—17 sept 2026
Memory corruption while processing rear sensor IOCTL calls.
CVE-2026-24075Alta (7)0.06%—17 sept 2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2025-59607Alta (7.8)0.07%—17 sept 2026
Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-24077Media (6.5)0.17%—4 ago 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24076Media (6.7)0.11%—4 ago 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21379Alta (7.8)0.10%—6 jul 2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2025-59613Media (6.7)0.08%—1 jun 2026
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612Media (6.7)0.08%—1 jun 2026
Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611Media (6.7)0.08%—1 jun 2026
Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2026-21378Alta (7.8)0.07%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21376Alta (7.8)0.10%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
CVE-2026-21375Alta (7.8)0.07%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374Alta (7.8)0.11%—6 abr 2026
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
CVE-2026-21373Alta (7.8)0.08%—6 abr 2026
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21371Alta (7.8)0.10%—6 abr 2026
Memory Corruption when retrieving output buffer with insufficient size validation.
CVE-2025-47390Alta (7.8)0.10%—6 abr 2026
Memory corruption while preprocessing IOCTL request in JPEG driver.
CVE-2025-47358Alta (7.8)0.10%—2 feb 2026
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.
CVE-2024-43050Alta (7.8)0.10%—2 dic 2024
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
CVE-2024-43049Alta (7.8)0.10%—2 dic 2024
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044Alta (7.8)0.10%—2 dic 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-38410Alta (7.8)0.10%—4 nov 2024
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
CVE-2024-38409Alta (7.8)0.10%—4 nov 2024
Memory corruption while station LL statistic handling.
CVE-2024-23357Media (5.5)0.09%—5 ago 2024
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2023-43536Alta (7.5)0.32%—6 feb 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43535Alta (7.8)0.11%—6 feb 2024
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
CVE-2023-43533Alta (7.5)0.32%—6 feb 2024
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-43532Alta (7.8)0.11%—6 feb 2024
Memory corruption while reading ACPI config through the user mode app.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation19
  2. T1059 Command and Scripting Interpreter16
  3. T1059.001 PowerShell1
  4. T1059.007 JavaScript1
  5. T1190 Exploit Public-Facing Application1
  6. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm