Vulnerabilidades en Qualcomm, Inc.

2976 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-14875—In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-EPSS 0.5%CVE-2017-15859—While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCAEPSS 0.5%CVE-2016-5862—When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, EPSS 0.5%CVE-2017-18170—Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SEPSS 0.5%CVE-2017-18283—Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212EPSS 0.5%CVE-2023-28588HIGHInteger Overflow or Wraparound in Bluetooth HostEPSS 0.5%CVE-2017-14869—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FEPSS 0.5%CVE-2015-0575—In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuraEPSS 0.5%CVE-2021-1906MEDIUMImproper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon ComputEPSS 0.5%KEVCVE-2021-35083HIGHPossible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon CoEPSS 0.5%CVE-2016-10336—In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.EPSS 0.5%CVE-2017-9679—In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory EPSS 0.5%CVE-2016-10337—In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.EPSS 0.5%CVE-2016-10332—In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.EPSS 0.5%CVE-2017-9680—In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a drEPSS 0.5%CVE-2017-18171—Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in SnapdragoEPSS 0.5%CVE-2020-11155—u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.' in Snapdragon AutoEPSS 0.5%CVE-2020-11154—u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon EPSS 0.5%CVE-2019-14040—Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in SnapEPSS 0.5%CVE-2022-22096CRITICALMemory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in SnapdragoEPSS 0.5%