« Volver al listado

Qualcomm

Qualcomm Sxr2130 Firmware: vulnerabilidades y CVE

Qualcomm Sxr2130 Firmware tiene 498 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 65 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE498
Últimos 12 meses3
Críticas65
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.
CVE-2023-33063Alta (7.8)0.67%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33106Alta (7.8)0.79%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27070Alta (7.8)0.06%—4 nov 2025
Memory corruption while performing encryption and decryption commands.
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27037Alta (7.8)0.09%—24 sept 2025
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
CVE-2025-27032Alta (7.8)0.08%—24 sept 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21481Alta (7.8)0.07%—24 sept 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27071Crítica (9.8)0.18%—6 ago 2025
Memory corruption while processing specific files in Powerline Communication Firmware.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21474Alta (7.8)0.09%—6 ago 2025
Memory corruption while processing commands from A2dp sink command queue.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21455Alta (7.8)0.07%—6 ago 2025
Memory corruption while submitting blob data to kernel space though IOCTL.
CVE-2025-21452Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21446Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21433Media (5.5)0.08%—8 jul 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21432Alta (7.8)0.09%—8 jul 2025
Memory corruption while retrieving the CBOR data from TA.
CVE-2025-21427Alta (8.2)0.22%—8 jul 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21422Alta (7.8)0.10%—8 jul 2025
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
CVE-2024-53009Alta (7.8)0.09%—8 jul 2025
Memory corruption while operating the mailbox in Automotive.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation47
  2. T1059 Command and Scripting Interpreter43
  3. T1190 Exploit Public-Facing Application20
  4. T1005 Data from Local System9
  5. T1499.004 Application or System Exploitation6
  6. T1499 Endpoint Denial of Service3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm