« Volver al listado

Qualcomm

Qualcomm Srv1l Firmware: vulnerabilidades y CVE

Qualcomm Srv1l Firmware tiene 164 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE164
Últimos 12 meses26
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25278Alta (7)0.05%—17 sept 2026
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVE-2026-21366Alta (7.8)0.10%—4 ago 2026
Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2025-59606Alta (7.8)0.07%—1 jun 2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
CVE-2025-59604Alta (7.8)0.07%—1 jun 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-47389Alta (7.8)0.10%—6 abr 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2025-47373Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
CVE-2025-47366Alta (7.8)0.10%—2 feb 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47364Alta (7.8)0.10%—2 feb 2026
Memory corruption while calculating offset from partition start point.
CVE-2025-47363Alta (7.8)0.10%—2 feb 2026
Memory corruption when calculating oversized partition sizes without proper checks.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345Alta (8.4)0.08%—7 ene 2026
Cryptographic issue may occur while encrypting license data.
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47382Alta (7.8)0.09%—18 dic 2025
Memory corruption while loading an invalid firmware in boot loader.
CVE-2025-47372Alta (8.4)0.11%—18 dic 2025
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
CVE-2025-47319Media (6.7)0.09%—18 dic 2025
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-47323Alta (7.8)0.09%—18 dic 2025
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47365Alta (7.8)0.08%—4 nov 2025
Memory corruption while processing large input data from a remote source via a communication interface.
CVE-2025-47362Media (6.1)0.08%—4 nov 2025
Information disclosure while processing message from client with invalid payload.
CVE-2025-47361Alta (7.8)0.08%—4 nov 2025
Memory corruption when triggering a subsystem crash with an out-of-range identifier.
CVE-2025-47360Alta (7.8)0.08%—4 nov 2025
Memory corruption while processing client message during device management.
CVE-2025-47357Alta (7.8)0.07%—4 nov 2025
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
CVE-2025-27070Alta (7.8)0.06%—4 nov 2025
Memory corruption while performing encryption and decryption commands.
CVE-2025-47347Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing control commands in the virtual memory management interface.
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-47315Alta (7.8)0.09%—24 sept 2025
Memory corruption while handling repeated memory unmap requests from guest VM.
CVE-2025-47314Alta (7.8)0.09%—24 sept 2025
Memory corruption while processing data sent by FE driver.
CVE-2025-27077Alta (7.8)0.09%—24 sept 2025
Memory corruption while processing message in guest VM.
CVE-2025-27032Alta (7.8)0.08%—24 sept 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation78
  2. T1059 Command and Scripting Interpreter70
  3. T1190 Exploit Public-Facing Application24
  4. T1005 Data from Local System9
  5. T1499.004 Application or System Exploitation9
  6. T1499 Endpoint Denial of Service4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm