Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-10554Multiple Read overflows issue due to improper length check while decoding Identity Request in CSdomain/Authentication Reject in CS domain/ PEPSS 1.0%CVE-2019-10553Multiple Read overflows due to improper length checks while decoding authentication in Cs domain/RAU Reject and TC cmd in Snapdragon Auto, SEPSS 1.0%CVE-2015-0574In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.EPSS 1.0%CVE-2015-9065In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access StrEPSS 1.0%CVE-2016-10381In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE EPSS 1.0%CVE-2016-10380In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE EPSS 1.0%CVE-2017-11089In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observeEPSS 1.0%CVE-2016-10384In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctEPSS 1.0%CVE-2016-10386In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.EPSS 1.0%CVE-2014-9972In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer derefEPSS 1.0%CVE-2016-10387In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenariEPSS 1.0%CVE-2016-10392In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.EPSS 1.0%CVE-2014-9971In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert EPSS 1.0%CVE-2014-9981In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient duriEPSS 1.0%CVE-2020-11188Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-11189Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-11171Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-11190Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-3628Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consumer IOT, Snapdragon EPSS 1.0%CVE-2019-14083While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is specifiedEPSS 1.0%