Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2018-5832—Due to a race condition in a camera driver ioctl handler in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS foEPSS 0.1%CVE-2021-30283HIGHPossible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer IOT, Snapdragon IndEPSS 0.1%CVE-2024-33035HIGHInteger Overflow or Wraparound in DisplayEPSS 0.1%CVE-2024-21476HIGHImproper Input Validation in Secure ProcessorEPSS 0.1%CVE-2022-25656HIGHPossible integer overflow and memory corruption due to improper validation of buffer size sent to write to console when computing the payloaEPSS 0.1%CVE-2022-25698HIGHMemory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, SnaEPSS 0.1%CVE-2017-11042—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExEPSS 0.1%CVE-2024-38401HIGHUse After Free in Qualcomm IPCEPSS 0.1%CVE-2022-25697HIGHMemory corruption in i2c buses due to improper input validation while reading address configuration from i2c driver in Snapdragon Mobile, SnEPSS 0.1%CVE-2024-33042HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2018-5859—Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM,EPSS 0.1%CVE-2022-25682HIGHMemory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon CEPSS 0.1%CVE-2022-25660HIGHMemory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial EPSS 0.1%CVE-2022-25695HIGHMemory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, SnapdragonEPSS 0.1%CVE-2022-25681HIGHPossible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caEPSS 0.1%CVE-2024-33052HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2022-25661HIGHMemory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdragonEPSS 0.1%CVE-2024-33054HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Computer VisionEPSS 0.1%CVE-2024-43055HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2021-35079MEDIUMImproper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in SnapdraEPSS 0.1%