Vulnerabilidades en Qualcomm, Inc.

2976 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2018-11925—Data length received from firmware is not validated against the max allowed size which can result in buffer overflow. in Snapdragon Auto, SnEPSS 0.2%CVE-2018-12013—Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, SnapdraEPSS 0.2%CVE-2017-18324—Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, EPSS 0.2%CVE-2017-18323—Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions EPSS 0.2%CVE-2017-18172—In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting in an Integer OverfloEPSS 0.2%CVE-2020-11181—Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in SnapEPSS 0.2%CVE-2018-11968—Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdragEPSS 0.2%CVE-2018-11966—Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdrEPSS 0.2%CVE-2018-11858—When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version EPSS 0.2%CVE-2020-11148—Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggEPSS 0.2%CVE-2018-11830—Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics ConnectivEPSS 0.2%CVE-2018-5914—Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using the incoming data in SEPSS 0.2%CVE-2018-12012—While updating blacklisting region shared buffered memory region is not validated against newly updated black list, causing boot-up to be coEPSS 0.2%CVE-2018-11857—Improper input validation in WLAN encrypt/decrypt module can lead to a buffer copy in Snapdragon Mobile in version SD 835, SD 845, SD 850EPSS 0.2%CVE-2018-13910—Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectivity, Snapdragon ConsEPSS 0.2%CVE-2020-11149—Out of bound access due to usage of an out-of-range pointer offset in the camera driver. in Snapdragon Auto, Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2018-11826—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on integer overfloEPSS 0.2%CVE-2020-11150—Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of poinEPSS 0.2%CVE-2018-3588—There is improper access control of the SSC and GPU mapped regions which lead to inject code from HLOS in Snapdragon Automobile, Snapdragon EPSS 0.2%CVE-2026-24079HIGHMissing Authentication for Critical Function in Data ModemEPSS 0.2%