Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-10509—Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivityEPSS 0.9%CVE-2020-3652—Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length EPSS 0.9%CVE-2020-3653—Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon CEPSS 0.9%CVE-2017-14910—In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD EPSS 0.9%CVE-2020-11285HIGHBuffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, SnapEPSS 0.9%CVE-2020-11227—Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, SEPSS 0.9%CVE-2020-11216—Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, EPSS 0.9%CVE-2020-11197—Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip wEPSS 0.9%CVE-2020-3671—Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon ConsuEPSS 0.9%CVE-2017-18146—In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607EPSS 0.9%CVE-2019-14013—While parsing invalid super index table, elements within super index table may exceed total chunk size and invalid data is read into the tabEPSS 0.9%CVE-2019-14134—Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE iEPSS 0.9%CVE-2019-10533—Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon CompEPSS 0.9%CVE-2020-11193—u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, SnapdraEPSS 0.9%CVE-2019-10589—Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdragon Auto, SnapdragoEPSS 0.9%CVE-2020-3639—u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overfloEPSS 0.9%CVE-2019-2325—Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, SnapdraEPSS 0.9%CVE-2019-2283—Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon AutEPSS 0.9%CVE-2019-2324—When ADSP is compromised, the audio port index that`s returned from ADSP might be out of the valid range and leads to out of boundary accessEPSS 0.9%CVE-2019-2323—Lack of check to ensure crypto engine data passed by user is initialized can result in bus error in Snapdragon Auto, Snapdragon Compute, SnaEPSS 0.9%