Vulnerabilidades en Qualcomm, Inc.

2976 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14089—u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a userEPSS 0.2%CVE-2021-1927HIGHPossible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.2%CVE-2021-30339CRITICALReading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IEPSS 0.2%CVE-2021-1934HIGHPossible memory corruption due to improper check when application loader object is explicitly destructed while application is unloading in SEPSS 0.2%CVE-2021-35114HIGHImproper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon AutoEPSS 0.2%CVE-2021-1895MEDIUMPossible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, SnapdrEPSS 0.2%CVE-2021-30315HIGHImproper handling of sensor HAL structure in absence of sensor can lead to use after free in Snapdragon AutoEPSS 0.2%CVE-2021-30291HIGHPossible memory corruption due to lack of validation of client data used for memory allocation in Snapdragon Auto, Snapdragon Compute, SnapdEPSS 0.2%CVE-2020-11240—Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy ofEPSS 0.2%CVE-2022-22085HIGHMemory corruption in video due to buffer overflow while reading the dts file in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivityEPSS 0.2%CVE-2021-35116HIGHAPK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, SEPSS 0.2%CVE-2020-11178—Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its EPSS 0.2%CVE-2024-38402HIGHUse After Free in DSP ServicesEPSS 0.2%CVE-2021-1947HIGHUse-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity,EPSS 0.2%CVE-2021-30316HIGHPossible out of bound memory access due to improper boundary check while creating HSYNC fence in Snapdragon Auto, Snapdragon Connectivity, SEPSS 0.2%CVE-2022-22082HIGHMemory corruption due to possible buffer overflow while parsing DSF header with corrupted channel count in Snapdragon Auto, Snapdragon CompuEPSS 0.2%CVE-2021-30292HIGHPossible memory corruption due to lack of validation of client data used for memory allocation in Snapdragon Auto, Snapdragon Compute, SnapdEPSS 0.2%CVE-2021-1952HIGHPossible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.2%CVE-2021-30257HIGHPossible out of bound read or write in VR service due to lack of validation of DSP selection values in Snapdragon Compute, Snapdragon ConnecEPSS 0.2%CVE-2021-35070MEDIUMRPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon IndEPSS 0.2%