Vulnerabilities in Qualcomm, Inc.

2,976 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2020-11253—Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivEPSS 0.2%CVE-2020-11194—Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon AutEPSS 0.2%CVE-2020-11223—Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon Auto, Snapdragon ComEPSS 0.2%CVE-2020-11195—Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in SnapEPSS 0.2%CVE-2020-11187—Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, SnapdragEPSS 0.2%CVE-2017-15844—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function foEPSS 0.2%CVE-2022-40540HIGHBuffer copy without checking the size of input in Linux KernelEPSS 0.2%CVE-2024-33060HIGHUse After Free in DSP ServiceEPSS 0.2%CVE-2017-9723—The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocateEPSS 0.2%CVE-2017-14872—While flashing a meta image, a buffer over-read can potentially occur when the number of images are out of the maximum range of 32 in AndroiEPSS 0.2%CVE-2021-1888HIGHMemory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, EPSS 0.2%CVE-2021-1890HIGHImproper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, SEPSS 0.2%CVE-2017-14893—While flashing meta image, a buffer over-read may potentially occur when the image size is smaller than the image header size or is smaller EPSS 0.2%CVE-2018-5895—Buffer over-read may happen in wma_process_utf_event() due to improper buffer length validation before writing into param_buf->num_wow_packeEPSS 0.2%CVE-2019-10575—Wlan binary which is not signed with OEMs RoT is working on secure device without authentication failure in Snapdragon Compute, Snapdragon CEPSS 0.2%CVE-2026-24078MEDIUMExposure of Private Personal Information to an Unauthorized Actor in Data ModemEPSS 0.2%CVE-2021-1886HIGHIncorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapdragon CompEPSS 0.2%CVE-2022-22068HIGHkernel event may contain unexpected content which is not generated by NPU software in asynchronous execution mode in Snapdragon Auto, SnapdrEPSS 0.2%CVE-2026-24077MEDIUMInteger Underflow (Wrap or Wraparound) in WLAN HostEPSS 0.2%CVE-2020-3626—Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, SnaEPSS 0.2%