Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2023-22382HIGHImproper Input Validation in AutomotiveEPSS 0.1%CVE-2023-43538CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in TZ Secure OSEPSS 0.1%CVE-2024-33034HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2024-33056HIGHBuffer Over-read in MProcEPSS 0.1%CVE-2023-43554HIGHImproper Restriction of Operations withing the Bounds of a Memory Buffer in DSP ServicesEPSS 0.1%CVE-2024-38425MEDIUMImproper Authorization in PerformanceEPSS 0.1%CVE-2020-11262—A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free isEPSS 0.1%CVE-2024-43049HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2024-45584HIGHUntrusted Pointer Dereference in Automotive Android OSEPSS 0.1%CVE-2024-49833HIGHImproper Validation of Array Index in CameraEPSS 0.1%CVE-2024-38422HIGHInteger Overflow to Buffer Overflow in AudioEPSS 0.1%CVE-2024-45550HIGHImproper Validation of Array Index in DSP ServicesEPSS 0.1%CVE-2024-33038HIGHUntrusted Pointer Dereference in Computer VisionEPSS 0.1%CVE-2025-21460HIGHImproper Input Validation in Automotive Software platform based on QNXEPSS 0.1%CVE-2024-43053HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows HostEPSS 0.1%CVE-2026-24083HIGHUntrusted Pointer Dereference in Automotive SecurityEPSS 0.1%CVE-2025-47359HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-38410HIGHStack-based Buffer Overflow in WLAN Windows HostEPSS 0.1%CVE-2024-43048HIGHStack-based Buffer Overflow in PerformanceEPSS 0.1%CVE-2024-43052HIGHImproper Input Validation in Video Analytics and ProcessingEPSS 0.1%