Vulnerabilidades en Qualcomm, Inc.

2976 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2025-21452HIGHReachable Assertion in ModemEPSS 0.2%CVE-2025-27073HIGHReachable Assertion in WLAN FirmwareEPSS 0.2%CVE-2025-21477HIGHImproper Input Validation in ModemEPSS 0.2%CVE-2020-3676—Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, SnapdragoEPSS 0.2%CVE-2020-11221—Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checEPSS 0.2%CVE-2020-11217—A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2020-11228—Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto, SnapdragEPSS 0.2%CVE-2018-13885—Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdragonEPSS 0.2%CVE-2018-11958—Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon ConsEPSS 0.2%CVE-2018-11971—Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in SnapdraEPSS 0.2%CVE-2020-3640—u'Resizing the usage table header before passing all the checks leads to the function exiting with a usage table in invalid state when a HLOEPSS 0.2%CVE-2018-11976—ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivitEPSS 0.2%CVE-2018-12004—Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics ConnectivEPSS 0.2%CVE-2019-13998—u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corrupEPSS 0.2%CVE-2019-14117—u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which resultEPSS 0.2%CVE-2019-10527—u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range whicEPSS 0.2%CVE-2019-13992—u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in Snapdragon Auto, SnaEPSS 0.2%CVE-2020-11175—u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due to impropEPSS 0.2%CVE-2019-10615—u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of keymasterEPSS 0.2%CVE-2020-11128—u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in Snapdragon Auto, SnaEPSS 0.2%