Vulnerabilidades em Qualcomm, Inc.

2.956 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2020-3657u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client thEPSS 28.3%CVE-2020-11117u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulEPSS 20.1%CVE-2020-11264CRITICALImproper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in SnapdEPSS 13.2%CVE-2020-11301CRITICALImproper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon AutoEPSS 11.1%CVE-2015-9222In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 20EPSS 4.4%CVE-2021-30351CRITICALAn out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon AutoEPSS 4.0%CVE-2017-8248A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th EPSS 3.1%CVE-2021-1965CRITICALPossible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 3.0%CVE-2020-11153u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution'EPSS 2.3%CVE-2017-14911In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SDEPSS 2.3%CVE-2020-11206Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, SnEPSS 1.8%CVE-2020-11201Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon CompuEPSS 1.8%CVE-2020-11261HIGHMemory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, EPSS 1.8%KEVCVE-2019-10529Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in SnaEPSS 1.7%CVE-2020-11208Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument' in SD82EPSS 1.7%CVE-2017-14913In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input valEPSS 1.7%CVE-2017-14912In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SDEPSS 1.7%CVE-2017-14915In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client stEPSS 1.6%CVE-2019-2307Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon AEPSS 1.6%CVE-2019-10574Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute, SnapdragonEPSS 1.6%