Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2015-9110In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450,EPSS 1.1%CVE-2019-2271Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, SEPSS 1.1%CVE-2019-2285Out of bound write issue is observed while giving information about properties that have been set so far for playing video in Snapdragon AutEPSS 1.1%CVE-2020-11299Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapEPSS 1.1%CVE-2020-11138Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability iEPSS 1.1%CVE-2020-11137Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possEPSS 1.1%CVE-2020-11225Out of bound access in WLAN driver due to lack of validation of array length before copying into array in Snapdragon Auto, Snapdragon ComputEPSS 1.1%CVE-2019-10532Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Snapdragon CoEPSS 1.1%CVE-2019-10534Null-pointer dereference can occur while accessing the super index entry when it is not been allocated in Snapdragon Auto, Snapdragon ComputEPSS 1.1%CVE-2019-2242Device memory may get corrupted because of buffer overflow/underflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer ElectronicEPSS 1.1%CVE-2018-11932Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, EPSS 1.1%CVE-2020-3667u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdragon Auto, SnEPSS 1.1%CVE-2026-21385HIGHInteger Overflow or Wraparound in GraphicsEPSS 1.1%KEVCVE-2020-3641Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, SnapdragonEPSS 1.1%CVE-2020-3634u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Snapdragon CEPSS 1.1%CVE-2020-3675u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, EPSS 1.1%CVE-2015-9063In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a procedure involvEPSS 1.1%CVE-2014-9976In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processingEPSS 1.1%CVE-2015-9066In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an Inter-RAT proceEPSS 1.1%CVE-2020-11143Out of bound memory access during music playback with modified content due to copying data without checking destination buffer size in SnapdEPSS 1.1%