Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2016-10380—In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE EPSS 1.0%CVE-2015-0574—In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.EPSS 1.0%CVE-2015-9065—In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access StrEPSS 1.0%CVE-2016-10381—In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE EPSS 1.0%CVE-2016-10456—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDEPSS 1.0%CVE-2016-10430—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450,EPSS 1.0%CVE-2017-11089—In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observeEPSS 1.0%CVE-2016-10386—In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.EPSS 1.0%CVE-2016-10384—In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctEPSS 1.0%CVE-2014-9972—In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer derefEPSS 1.0%CVE-2016-10392—In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.EPSS 1.0%CVE-2016-10387—In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenariEPSS 1.0%CVE-2014-9971—In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert EPSS 1.0%CVE-2014-9981—In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient duriEPSS 1.0%CVE-2020-11188—Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-11171—Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2020-11189—Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2015-9138—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear, and SmalEPSS 1.0%CVE-2020-11190—Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon CoEPSS 1.0%CVE-2019-14083—While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is specifiedEPSS 1.0%