Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-30350HIGHLack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon CEPSS 0.2%CVE-2021-30349HIGHImproper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, SnapdragEPSS 0.2%CVE-2021-35130HIGHMemory corruption in graphics support layer due to use after free condition in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon IndustriEPSS 0.2%CVE-2021-30334HIGHPossible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, SEPSS 0.2%CVE-2021-1913HIGHPossible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, EPSS 0.2%CVE-2021-35091HIGHPossible out of bounds read due to improper typecasting while handling page fault for global memory in Snapdragon Connectivity, Snapdragon MEPSS 0.2%CVE-2021-30281HIGHPossible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configurationEPSS 0.2%CVE-2023-33092HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.2%CVE-2023-33088HIGHNULL pointer dereference in WLAN FirmwareEPSS 0.2%CVE-2021-35126HIGHMemory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivEPSS 0.2%CVE-2021-35129HIGHMemory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2017-11035In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, possible buffer overflow or EPSS 0.2%CVE-2021-1932HIGHImproper access control in trusted application environment can cause unauthorized access to CDSP or ADSP VM memory with either privilege in EPSS 0.2%CVE-2017-15852Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.EPSS 0.2%CVE-2020-11284HIGHLocked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusteEPSS 0.2%CVE-2017-11075In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security pEPSS 0.2%CVE-2018-5825In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security pEPSS 0.2%CVE-2021-35080MEDIUMDisabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, SnapdrEPSS 0.2%CVE-2021-1909HIGHBuffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2017-11017In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially cEPSS 0.2%