Vulnerabilidades en Qualcomm, Inc.

2976 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2020-11120—u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffEPSS 0.2%CVE-2018-11281—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while calling IPA_IOC_MDFY_RT_RUEPSS 0.2%CVE-2020-3636—u'Out of bound writes happen when accessing usage_table header entry beyond the memory allocated for the header' in Snapdragon Auto, SnapdraEPSS 0.2%CVE-2020-3696—u'Use after free while installing new security rule in ipcrtr as old one is deleted and this rule could still be in use for checking securitEPSS 0.2%CVE-2019-10571—Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Auto, Snapdragon CompuEPSS 0.2%CVE-2019-10563—Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firmware in Snapdragon AEPSS 0.2%CVE-2020-3630—Possibility of out of bound access while processing the responses from video firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon ConEPSS 0.2%CVE-2020-3635—Stack based overflow If the maximum number of arguments allowed per request in perflock exceeds in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.2%CVE-2019-10503—Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer ElectronicEPSS 0.2%CVE-2019-14048—Possible out of bound memory access while playing a crafted clip in media player in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsumerEPSS 0.2%CVE-2019-14094—Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdragon Auto, EPSS 0.2%CVE-2021-35106HIGHPossible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivitEPSS 0.2%CVE-2020-11162—u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI device side' in SnapdragoEPSS 0.2%CVE-2019-10547—When issuing IOCTL calls to ION, Memory leak can occur due to failure in unassign pages under certain conditions in Snapdragon Auto, SnapdraEPSS 0.2%CVE-2020-3624—u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage in operation' in SnapEPSS 0.2%CVE-2019-10592—Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check on the maximum modeEPSS 0.2%CVE-2019-2319—HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon ConsEPSS 0.2%CVE-2020-3647—u'Potential buffer overflow when accessing npu debugfs node "off"/"log" with large buffer size' in Snapdragon Compute, Snapdragon IndustrialEPSS 0.2%CVE-2020-11210CRITICALPossible memory corruption in RPM region due to improper XPU configuration in Snapdragon Connectivity, Snapdragon Industrial IOT, SnapdragonEPSS 0.2%CVE-2019-10584—Possibility of out of bound access in debug queue, if packet size field is corrupted in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnEPSS 0.2%