Vulnerabilidades en Qualcomm, Inc.

2934 resultados
Análisis Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-30266MEDIUMPossible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, SnapEPSS 0.2%CVE-2017-11007In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of stEPSS 0.2%CVE-2019-2318Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity,EPSS 0.2%CVE-2021-1969MEDIUMImproper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure toEPSS 0.2%CVE-2018-5887While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernEPSS 0.2%CVE-2018-5888While processing the system path, an out of bounds access can occur in Android releases from CAF using the linux kernel (Android for MSM, FiEPSS 0.2%CVE-2019-10484Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previoEPSS 0.2%CVE-2017-18154A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, EPSS 0.2%CVE-2022-22078MEDIUMDenial of service in BOOT when partition size for a particular partition is requested due to integer overflow when blocks are calculated in EPSS 0.2%CVE-2019-2336Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon CompuEPSS 0.2%CVE-2025-27071HIGHBuffer Copy Without Checking Size of Input in Powerline Communication FirmwareEPSS 0.2%CVE-2019-10535Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop iEPSS 0.2%CVE-2022-25664MEDIUMInformation disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.2%CVE-2021-1968MEDIUMImproper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure toEPSS 0.2%CVE-2024-21455HIGHUntrusted Pointer Dereference in DSP ServiceEPSS 0.2%CVE-2018-3573In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while relocating kernel images wEPSS 0.2%CVE-2017-15851Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android rEPSS 0.2%CVE-2018-5899In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-0EPSS 0.2%CVE-2018-5843In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using thEPSS 0.2%CVE-2020-11266Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired InfrastructEPSS 0.2%