Qualcomm
Qualcomm Snapdragon High MED 2016 Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon High MED 2016 Firmware tiene 100 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 31 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE100
Últimos 12 meses0
Críticas31
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-11076 | Crítica (9.8) | 0.35% | — | 26 nov 2024 | On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| CVE-2019-2337 | Alta (7.5) | 0.66% | — | 12 dic 2019 | While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device to shutdown in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,… |
| CVE-2019-2321 | Alta (7.8) | 0.20% | — | 12 dic 2019 | Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics… |
| CVE-2019-2320 | Crítica (9.8) | 0.91% | — | 12 dic 2019 | Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2019-2288 | Alta (7.8) | 0.20% | — | 12 dic 2019 | Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2019-10511 | Crítica (9.8) | 0.91% | — | 12 dic 2019 | Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… |
| CVE-2019-10493 | Crítica (9.8) | 0.91% | — | 12 dic 2019 | Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in… |
| CVE-2019-10485 | Alta (7.5) | 0.66% | — | 12 dic 2019 | Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice… |
| CVE-2019-2335 | Alta (7.5) | 0.65% | — | 21 nov 2019 | While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… |
| CVE-2019-2318 | Media (5.5) | 0.17% | — | 21 nov 2019 | Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-2315 | Alta (7.8) | 0.20% | — | 21 nov 2019 | While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure environment. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-2303 | Crítica (9.8) | 0.71% | — | 21 nov 2019 | SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-2295 | Media (5.5) | 0.19% | — | 21 nov 2019 | Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2019-2289 | Crítica (9.8) | 0.61% | — | 21 nov 2019 | Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2271 | Crítica (9.8) | 1.1% | — | 21 nov 2019 | Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2018-13916 | Alta (7.8) | 0.22% | — | 21 nov 2019 | Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer… |
| CVE-2019-2285 | Crítica (9.8) | 1.1% | — | 6 nov 2019 | Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-2275 | Media (5.5) | 0.19% | — | 6 nov 2019 | While deserializing any key blob during key operations, buffer overflow could occur exposing partial key information if any key operations are invoked(Depends on CVE-2018-13907) in Snapdragon Auto, Snapdragon Compute,… |
| CVE-2019-2258 | Crítica (9.8) | 0.91% | — | 6 nov 2019 | Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon… |
| CVE-2019-2249 | Crítica (9.8) | 1.4% | — | 6 nov 2019 | Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-2246 | Alta (7.8) | 0.20% | — | 6 nov 2019 | Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-10504 | Media (6.5) | 0.55% | — | 6 nov 2019 | Firmware not able to send EXT scan response to host within 1 sec due to resource consumption issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… |
| CVE-2019-10496 | Alta (7.8) | 0.19% | — | 6 nov 2019 | Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… |
| CVE-2019-10495 | Alta (7.3) | 0.19% | — | 6 nov 2019 | Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… |
| CVE-2019-2294 | Crítica (9.8) | 0.91% | — | 30 sept 2019 | Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon… |
| CVE-2019-2252 | Crítica (9.8) | 1.2% | — | 30 sept 2019 | Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2019-10509 | Crítica (9.8) | 0.92% | — | 30 sept 2019 | Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… |
| CVE-2019-2343 | Media (5.5) | 0.19% | — | 25 jul 2019 | Out of bound read and information disclosure in firmware due to insufficient checking of an embedded structure that can be sent from a kernel driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,… |
| CVE-2019-2334 | Alta (7.5) | 0.82% | — | 25 jul 2019 | Null pointer dereferencing can happen when playing the clip with wrong block group id in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… |
| CVE-2019-2327 | Crítica (9.8) | 0.93% | — | 25 jul 2019 | Possible buffer overflow can occur when playing clip with incorrect element size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.