« Volver al listado

Qualcomm

Qualcomm Wsa8845 Firmware: vulnerabilidades y CVE

Qualcomm Wsa8845 Firmware tiene 504 vulnerabilidades publicadas, 142 de ellas en los últimos 12 meses. 23 son críticas y 6 figuran en el catálogo de explotación activa de CISA.

CVE504
Últimos 12 meses142
Críticas23
Explotadas activamente6

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-21480Alta (8.6)0.46%⚠ Explotación activa3 jun 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21479Alta (8.6)0.84%⚠ Explotación activa3 jun 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33106Alta (7.8)0.92%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.89%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-25294Alta (7.4)0.10%—17 sept 2026
Transient DOS while parsing frame during channel usage.
CVE-2026-25290Alta (7.8)0.07%—17 sept 2026
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2026-25284Alta (7.3)0.07%—17 sept 2026
Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25283Alta (8.8)0.07%—17 sept 2026
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25282Alta (7.9)0.06%—17 sept 2026
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25281Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
CVE-2026-25280Alta (7.8)0.07%—17 sept 2026
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVE-2026-25275Alta (7.5)0.19%—17 sept 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25261Alta (7.8)0.07%—17 sept 2026
Memory corruption while processing rear sensor IOCTL calls.
CVE-2026-24081Alta (7.4)0.10%—17 sept 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVE-2026-24075Alta (7)0.06%—17 sept 2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-24074Alta (7.8)0.07%—17 sept 2026
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVE-2026-24073Alta (7.8)0.07%—17 sept 2026
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2025-59607Alta (7.8)0.07%—17 sept 2026
Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-25292Alta (7.6)0.15%—4 ago 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-25289Crítica (9.6)0.19%—4 ago 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25288Alta (7.4)0.16%—4 ago 2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084Alta (7.5)0.25%—4 ago 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24080Alta (7.8)0.10%—4 ago 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079Alta (8.1)0.21%—4 ago 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Media (6.5)0.17%—4 ago 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Media (6.5)0.17%—4 ago 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24076Media (6.7)0.11%—4 ago 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-25271Alta (7)0.07%—6 jul 2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
CVE-2026-21384Media (5.3)0.08%—6 jul 2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
CVE-2026-21379Alta (7.8)0.10%—6 jul 2026
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-21370Media (5.3)0.08%—6 jul 2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVE-2026-21369Media (5.3)0.08%—6 jul 2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
CVE-2026-21368Media (5.3)0.08%—6 jul 2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2025-59617Alta (7.3)0.09%—6 jul 2026
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation208
  2. T1059 Command and Scripting Interpreter199
  3. T1190 Exploit Public-Facing Application47
  4. T1499.004 Application or System Exploitation27
  5. T1005 Data from Local System17
  6. T1210 Exploitation of Remote Services8

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm