Vulnerabilities in Qualcomm, Inc.

2,976 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-35110HIGHPossible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon MobilEPSS 0.2%CVE-2024-23380HIGHUse After Free in GraphicsEPSS 0.2%CVE-2022-22072HIGHBuffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2021-30261HIGHPossible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in SEPSS 0.2%CVE-2021-1892HIGHMemory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdragon ConnecEPSS 0.2%CVE-2021-30256HIGHPossible stack overflow due to improper validation of camera name length before copying the name in VR Service in Snapdragon Compute, SnapdrEPSS 0.2%CVE-2021-1983HIGHPossible buffer overflow due to improper handling of negative data length while processing write request in VR service in Snapdragon Auto, SEPSS 0.2%CVE-2021-35102HIGHPossible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, SnapdrEPSS 0.2%CVE-2021-30295HIGHPossible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon Auto, SnapdEPSS 0.2%CVE-2021-35072HIGHPossible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon ConEPSS 0.2%CVE-2018-11304—Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overfloEPSS 0.2%CVE-2021-30288HIGHPossible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon CEPSS 0.2%CVE-2021-1915HIGHBuffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2021-1984HIGHPossible buffer overflow due to improper validation of index value while processing the plugin block in Snapdragon Auto, Snapdragon Compute,EPSS 0.2%CVE-2026-25288HIGHBuffer Over-read in WLAN FirmwareEPSS 0.2%CVE-2021-30258HIGHPossible buffer overflow due to improper size calculation of payload received in VR service in Snapdragon Auto, Snapdragon Compute, SnapdragEPSS 0.2%CVE-2020-11165—Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the length of buffer in SEPSS 0.2%CVE-2018-5898—Integer overflow can occur in msm_pcm_adsp_stream_cmd_put() function if the user supplied data "param_length" goes beyond certain limit in AEPSS 0.2%CVE-2020-3619—u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or memory corruption' iEPSS 0.2%CVE-2018-3579—In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, event->num_enEPSS 0.2%