Vulnerabilidades en Qualcomm, Inc.

2934 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2016-5867In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that couldEPSS 0.6%CVE-2021-1955HIGHDenial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon Compute, SEPSS 0.6%CVE-2021-1887HIGHAn assertion can be reached in the WLAN subsystem while using the Wi-Fi Fine Timing Measurement protocol in Snapdragon Wired Infrastructure EPSS 0.6%CVE-2021-1943HIGHPossible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in SnapdraEPSS 0.6%CVE-2021-1945HIGHPossible out of bound read due to lack of length check of Bandwidth-NSS IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, EPSS 0.6%CVE-2015-9033In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.EPSS 0.6%CVE-2014-9967In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.EPSS 0.6%CVE-2015-9020In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.EPSS 0.6%CVE-2016-10238In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.EPSS 0.6%CVE-2016-10383In all Qualcomm products with Android releases from CAF using the Linux kernel, there is a TOCTOU race condition in Secure UI.EPSS 0.6%CVE-2021-1941HIGHPossible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.6%CVE-2021-1936HIGHNull pointer dereference can occur due to lack of null check for user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnEPSS 0.6%CVE-2021-1971HIGHPossible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdragoEPSS 0.6%CVE-2021-1948HIGHPossible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snapdragon ComEPSS 0.6%CVE-2014-9933Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not havEPSS 0.6%CVE-2015-9002In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the EPSS 0.6%CVE-2015-9003In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.EPSS 0.6%CVE-2016-10338In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.EPSS 0.6%CVE-2015-9000In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using thEPSS 0.6%CVE-2016-10341In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.EPSS 0.6%