Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2022-22070HIGHMemory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, SnEPSS 0.1%CVE-2023-28556HIGHImproper Authorization in HLOSEPSS 0.1%CVE-2022-22081HIGHMemory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon WearablEPSS 0.1%CVE-2024-53022HIGHImproper Input Validation in Automotive OS PlatformEPSS 0.1%CVE-2024-53014HIGHImproper Validation of Array Index in AudioEPSS 0.1%CVE-2022-22080HIGHImproper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2022-22104HIGHMemory corruption in multimedia due to improper check on the messages received. in Snapdragon AutoEPSS 0.1%CVE-2021-35133MEDIUMUse after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon ConnEPSS 0.1%CVE-2022-22089HIGHMemory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, EPSS 0.1%CVE-2022-22098HIGHMemory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon AutoEPSS 0.1%CVE-2022-33210HIGHMemory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large EPSS 0.1%CVE-2024-53030HIGHImproper Input Validation in Automotive OS PlatformEPSS 0.1%CVE-2022-22061HIGHOut of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, SnaEPSS 0.1%CVE-2022-22066HIGHMemory corruption occurs while processing command received from HLOS due to improper length check in Snapdragon Auto, Snapdragon Compute, SnEPSS 0.1%CVE-2022-25693HIGHMemory corruption in graphics due to use-after-free while graphics profiling in Snapdragon Connectivity, Snapdragon MobileEPSS 0.1%CVE-2022-22100HIGHMemory corruption in multimedia due to improper check on received export descriptors in Snapdragon AutoEPSS 0.1%CVE-2022-22097HIGHMemory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOTEPSS 0.1%CVE-2017-9691—There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debuEPSS 0.1%CVE-2021-35132HIGHOut of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2022-22092HIGHMemory corruption in kernel due to use after free issue in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, SnapdragoEPSS 0.1%