Qualcomm
Qualcomm Wcn3660 Firmware: vulnerabilidades y CVE
Qualcomm Wcn3660 Firmware tiene 128 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 37 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE128
Últimos 12 meses0
Críticas37
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21433 | Media (5.5) | 0.08% | — | 8 jul 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| CVE-2024-23357 | Media (5.5) | 0.09% | — | 5 ago 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-33023 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption while processing finish_sign command to pass a rsp buffer. |
| CVE-2023-28547 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption in SPS Application while requesting for public key in sorter TA. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-33110 | Alta (7) | 0.08% | — | 2 ene 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close… |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33030 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in HLOS while running playready use-case. |
| CVE-2023-28546 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. |
| CVE-2023-24850 | Alta (7.8) | 0.12% | — | 3 oct 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. |
| CVE-2023-33021 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in Graphics while processing user packets for command submission. |
| CVE-2023-33020 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. |
| CVE-2023-33019 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. |
| CVE-2023-28537 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. |
| CVE-2023-22666 | Alta (7.8) | 0.12% | — | 8 ago 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. |
| CVE-2023-21626 | Alta (7.1) | 0.11% | — | 8 ago 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| CVE-2022-40510 | Crítica (9.8) | 0.43% | — | 8 ago 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2023-22667 | Alta (7.8) | 0.12% | — | 4 jul 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| CVE-2023-21629 | Media (6.8) | 0.19% | — | 4 jul 2023 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.