« Volver al listado

Qualcomm

Qualcomm Vision Intelligence 300 Platform Firmware: vulnerabilidades y CVE

Qualcomm Vision Intelligence 300 Platform Firmware tiene 81 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE81
Últimos 12 meses3
Críticas2
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33107Alta (7.8)0.89%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47320Alta (7.8)0.08%—18 dic 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27032Alta (7.8)0.08%—24 sept 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53010Alta (7.8)0.08%—3 jun 2025
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-43046Media (5.5)0.11%—7 abr 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33058Alta (7.5)0.09%—7 abr 2025
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044Alta (7.8)0.10%—2 dic 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-38423Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23362Alta (7.1)0.12%—2 sept 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-33027Alta (7.8)0.10%—5 ago 2024
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21481Alta (8.4)0.11%—5 ago 2024
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
CVE-2024-23368Alta (7.8)0.10%—1 jul 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.
CVE-2024-21469Alta (7.8)0.10%—1 jul 2024
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
CVE-2024-21465Alta (7.8)0.10%—1 jul 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43536Alta (7.5)0.32%—6 feb 2024
Transient DOS while parse fils IE with length equal to 1.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation12
  2. T1059 Command and Scripting Interpreter10
  3. T1190 Exploit Public-Facing Application5
  4. T1005 Data from Local System3
  5. T1499 Endpoint Denial of Service1
  6. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm