Vulnerabilidades en Qualcomm, Inc.

2934 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2022-25673HIGHDenial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon MobileEPSS 0.4%CVE-2022-40513HIGHUncontrolled resource consumption in WLAN Firmware.EPSS 0.4%CVE-2025-27034CRITICALImproper Validation of Array Index in Multi-Mode Call ProcessorEPSS 0.4%CVE-2025-21483CRITICALImproper Restriction of Operations within the Bounds of a Memory Buffer in Data Network Stack & ConnectivityEPSS 0.4%CVE-2014-9927In UIM in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentiallyEPSS 0.4%CVE-2023-28572MEDIUMBuffer Over-read in WLAN HOSTEPSS 0.4%CVE-2022-22057HIGHUse after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously inEPSS 0.4%CVE-2022-40536HIGHImproper authentication in ModemEPSS 0.4%CVE-2017-8237In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.EPSS 0.4%CVE-2017-8236In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.EPSS 0.4%CVE-2022-22091HIGHImproper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, SnapdEPSS 0.4%CVE-2022-25669HIGHDenial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SEPSS 0.4%CVE-2022-25749HIGHTransient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.4%CVE-2018-11293In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in wma_ndp_confirm_event_handlerEPSS 0.4%CVE-2023-33025CRITICALBuffer Copy without Checking Size of Input in Data ModemEPSS 0.4%CVE-2018-11982In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SDEPSS 0.4%CVE-2018-5841dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could leaEPSS 0.4%CVE-2018-5840Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (AndEPSS 0.4%CVE-2017-15860In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management framEPSS 0.4%CVE-2016-10242A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the LinuEPSS 0.4%