Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14091—Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2024-33016MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in StorageEPSS 0.2%CVE-2021-30260HIGHPossible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuratEPSS 0.2%CVE-2017-9704—In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization betweEPSS 0.2%CVE-2017-9705—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, concurrent rx notifications EPSS 0.2%CVE-2021-1962MEDIUMBuffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for input maximum endpoint EPSS 0.2%CVE-2021-1966MEDIUMPossible buffer overflow due to lack of length check of source and destination buffer before copying in Snapdragon Auto, Snapdragon Compute,EPSS 0.2%CVE-2021-35094HIGHImproper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, SEPSS 0.2%CVE-2020-11231MEDIUMTwo threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap EPSS 0.2%CVE-2017-15845—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmwareEPSS 0.2%CVE-2021-30271HIGHPossible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, SnapdragonEPSS 0.2%CVE-2021-30269HIGHPossible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, SnapdragonEPSS 0.2%CVE-2018-13893—In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caEPSS 0.2%CVE-2018-5863—If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Android releases(Android EPSS 0.2%CVE-2017-15848—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the fastrpc kernel driverEPSS 0.2%CVE-2021-30270HIGHPossible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon AEPSS 0.2%CVE-2021-30272HIGHPossible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon Auto, SnaEPSS 0.2%CVE-2021-35121MEDIUMAn array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon CEPSS 0.1%CVE-2020-11160—Resource leakage issue during dci client registration due to reference count is not decremented if dci client registration fails in SnapdragEPSS 0.1%CVE-2017-8244—In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_bEPSS 0.1%