Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14114—Buffer overflow in WLAN firmware while parsing GTK IE containing GTK key having length more than the buffer size in Snapdragon Auto, SnapdraEPSS 0.9%CVE-2019-14014—Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon ConsumerEPSS 0.9%CVE-2019-14031—Buffer overflow can occur while parsing RSN IE containing list of PMK ID`s which are more than the buffer size in Snapdragon Auto, SnapdragoEPSS 0.9%CVE-2020-3654—u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon EPSS 0.9%CVE-2019-10586—Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdragon Auto,EPSS 0.9%CVE-2019-10588—Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow. in SnEPSS 0.9%CVE-2019-10525—Buffer overflow during SIB read when network configures complete sib list along with first and last segment of other SIB in Snapdragon Auto,EPSS 0.9%CVE-2019-14111—Possible buffer overflow while handling NAN reception of NMF in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon ConEPSS 0.9%CVE-2019-10593—Buffer overflow can occur when processing non standard SDP video Image attribute parameter in a VILTE\VOLTE call in Snapdragon Auto, SnapdraEPSS 0.9%CVE-2019-10611—Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon Compute, SEPSS 0.9%CVE-2019-10539—Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon Auto, Snapdragon ComEPSS 0.9%CVE-2019-10546—Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto, Snapdragon Compute,EPSS 0.9%CVE-2019-10587—Possible Stack overflow can occur when processing a large SDP body or non standard SDP body without right delimiters in Snapdragon Auto, SnaEPSS 0.9%CVE-2019-14045—Possible buffer overflow while processing clientlog and serverlog due to lack of validation of data received in logs in Snapdragon Auto, SnaEPSS 0.9%CVE-2020-11196—u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, SnapdEPSS 0.9%CVE-2019-14113—Buffer overflow can occur in In WLAN firmware while unwraping data using CCMP cipher suite during parsing of EAPOL handshake frame in SnapdrEPSS 0.9%CVE-2019-10531—Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile,EPSS 0.9%CVE-2019-10612—UTCB object has a function pointer called by the reaper to deallocate its memory resources and this address can potentially be corrupted by EPSS 0.9%CVE-2019-2300—Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in Snapdragon Auto, SnaEPSS 0.9%CVE-2019-10559—Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corruption in SnEPSS 0.9%