Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2015-9048—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packetsEPSS 0.8%CVE-2015-9049—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responseEPSS 0.8%CVE-2016-5872—In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validateEPSS 0.8%CVE-2015-9052—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reacEPSS 0.8%CVE-2015-9039—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reEPSS 0.8%CVE-2015-9046—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reacEPSS 0.8%CVE-2014-9974—In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing in Keymaster.EPSS 0.8%CVE-2015-9037—In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlinkEPSS 0.8%CVE-2016-10391—In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for valEPSS 0.8%CVE-2015-9072—In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syEPSS 0.8%CVE-2015-9050—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access cEPSS 0.8%CVE-2015-9070—In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscaEPSS 0.8%CVE-2014-9979—In all Qualcomm products with Android releases from CAF using the Linux kernel, a variable is uninitialized in a TrustZone system call potenEPSS 0.8%CVE-2016-10347—In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validatEPSS 0.8%CVE-2016-10343—In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in EPSS 0.8%CVE-2016-10344—In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially posEPSS 0.8%CVE-2014-9980—In all Qualcomm products with Android releases from CAF using the Linux kernel, a Sample App failed to check a length potentially leading toEPSS 0.8%CVE-2015-9069—In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrupted.EPSS 0.8%CVE-2015-9060—In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.EPSS 0.8%CVE-2015-9071—In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscaEPSS 0.8%