Vulnerabilities in Qualcomm, Inc.

2,976 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2022-33245MEDIUMUse after free in WLANEPSS 0.1%CVE-2022-33260MEDIUMStack based buffer overflow in CoreEPSS 0.1%CVE-2023-28577MEDIUMMultiple Dmabuf Kernel Address UAF VulnerabilityEPSS 0.1%CVE-2022-25665MEDIUMInformation disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon MobileEPSS 0.1%CVE-2022-33225MEDIUMUse after free in Trusted Application EnvironmentEPSS 0.1%CVE-2021-30299MEDIUMImproper Input Validation in AudioEPSS 0.1%CVE-2022-25724HIGHMemory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2023-33032CRITICALInteger Overflow or Wraparound in TZ Secure OSEPSS 0.1%CVE-2023-28575MEDIUMMultiple Type Confusion VulnerabilityEPSS 0.1%CVE-2024-23375MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in RILEPSS 0.1%CVE-2024-33045HIGHReturn of Stack Variable Address in BusesEPSS 0.1%CVE-2022-25653MEDIUMInformation disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity, SnapdragonEPSS 0.1%CVE-2022-33217HIGHMemory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernEPSS 0.1%CVE-2022-22075MEDIUMInformation Exposure in GraphicsEPSS 0.1%CVE-2022-33221MEDIUMBuffer over-read in Trusted Execution EnvironmentEPSS 0.1%CVE-2024-45549HIGHExposure of Sensitive System Information to an Unauthorized Control Sphere in KERNELEPSS 0.1%CVE-2022-25723HIGHMemory corruption in multimedia due to use after free during callback registration failure in Snapdragon MobileEPSS 0.1%CVE-2024-23369HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in HLOSEPSS 0.1%CVE-2020-11277—Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in SnapEPSS 0.1%CVE-2022-33273HIGHBuffer over-read in Trusted Execution EnvironmentEPSS 0.1%