Vulnerabilities in Qualcomm, Inc.

2,976 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-14888—In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the hosEPSS 0.2%CVE-2017-18277—When dynamic memory allocation fails, currently the process sleeps for one second and continues with infinite loop without retrying for memoEPSS 0.2%CVE-2018-5893—While processing a message from firmware in htt_t2h_msg_handler_fast() in Android releases from CAF using the linux kernel (Android for MSM,EPSS 0.2%CVE-2018-12014—In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerabEPSS 0.2%CVE-2020-3664—Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon ComEPSS 0.2%CVE-2015-9218—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 20EPSS 0.2%CVE-2017-15828—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing the keystore in EPSS 0.2%CVE-2026-25293CRITICALIncorrect authorization in PLC FWEPSS 0.2%CVE-2020-11259—Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and NetworkingEPSS 0.2%CVE-2021-35097HIGHPossible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon EPSS 0.2%CVE-2020-11282—Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPUEPSS 0.2%CVE-2020-11258—Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and NetworkingEPSS 0.2%CVE-2020-11257—Memory corruption due to lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and NetworkingEPSS 0.2%CVE-2018-13927—Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in SnaEPSS 0.2%CVE-2018-13895—Due to the missing permissions on several content providers of the RCS app in its android manifest file will lead to an unprivileged access EPSS 0.2%CVE-2019-2257—Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity, Snapdragon ConsumerEPSS 0.2%CVE-2025-27071HIGHBuffer Copy Without Checking Size of Input in Powerline Communication FirmwareEPSS 0.2%CVE-2017-9693—The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android beEPSS 0.2%CVE-2022-25664MEDIUMInformation disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.2%CVE-2021-35069HIGHImproper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%