Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2024-45579HIGHImproper Input Validation in Camera DriverEPSS 0.1%CVE-2025-47384MEDIUMReachable Assertion in FWEPSS 0.1%CVE-2023-33118HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2024-45544MEDIUMUse After Free in Data Network Stack & ConnectivityEPSS 0.1%CVE-2023-33031HIGHBuffer Copy Without Checking Size of Input in Automotive AudioEPSS 0.1%CVE-2024-45574HIGHImproper Validation of Array Index in Camera DriverEPSS 0.1%CVE-2018-11816HIGHUse After Free in VideoEPSS 0.1%CVE-2024-45564HIGHUse After Free in HLOSEPSS 0.1%CVE-2023-33034HIGHSigned-to-unsigned conversion error in AudioEPSS 0.1%CVE-2023-43550HIGHInteger Overflow or Wraparound in Core ServicesEPSS 0.1%CVE-2023-33117HIGHUse After Free in AudioEPSS 0.1%CVE-2023-33077MEDIUMBuffer Copy Without Checking Size of Input in HLOSEPSS 0.1%CVE-2024-21482MEDIUMImproper Restriction of Operations within the Bounds of a Memory Buffer in Linux Boot LoaderEPSS 0.1%CVE-2023-33068MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-21626HIGHImproper Authentication in HLOS.EPSS 0.1%CVE-2024-49829MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in CameraEPSS 0.1%CVE-2023-43530MEDIUMInteger Overflow or Wraparound in HLOSEPSS 0.1%CVE-2023-43524MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2024-45568MEDIUMBuffer Over-read in Camera DriverEPSS 0.1%CVE-2024-45541HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN Windows HostEPSS 0.1%