Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2015-9140—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDMEPSS 0.8%CVE-2019-10488—Null pointer dereference can occur while parsing invalid chunks while playing the nonstandard clip in Snapdragon Auto, Snapdragon Compute, SEPSS 0.8%CVE-2021-1972CRITICALPossible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon ConEPSS 0.8%CVE-2021-35104CRITICALPossible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, SnapdrEPSS 0.8%CVE-2021-35081CRITICALPossible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in SnapdragEPSS 0.8%CVE-2020-11182—Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon ComEPSS 0.8%CVE-2018-11271—Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon ComputeEPSS 0.8%CVE-2015-8592—In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potenEPSS 0.8%CVE-2015-9047—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after EPSS 0.8%CVE-2015-9040—In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.EPSS 0.8%CVE-2016-10382—In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.EPSS 0.8%CVE-2021-1946CRITICALNull Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.8%CVE-2021-1920CRITICALInteger underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivitEPSS 0.8%CVE-2020-11159—Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer beinEPSS 0.8%CVE-2018-11291—In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6EPSS 0.8%CVE-2021-1933CRITICALUE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon ConneEPSS 0.8%CVE-2021-1976CRITICALA use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.8%CVE-2020-11126—Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, EPSS 0.8%CVE-2020-11134—Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup atEPSS 0.8%CVE-2021-1919CRITICALInteger underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, SnapdEPSS 0.8%