Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2016-10443—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM92EPSS 0.7%CVE-2015-9134—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 410/12, SD 615/16/SD 415, and SD 810, while prEPSS 0.7%CVE-2019-10522—While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsuEPSS 0.7%CVE-2019-14080—Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdragon Auto, Snapdragon CEPSS 0.7%CVE-2019-10565—Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, SnapEPSS 0.7%CVE-2019-10528—Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, SnaEPSS 0.7%CVE-2019-2268—Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics ConnecEPSS 0.7%CVE-2020-3703—u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from centralEPSS 0.7%CVE-2019-2303—SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, SnapdragEPSS 0.7%CVE-2019-10542—Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in SnEPSS 0.7%CVE-2020-11255HIGHDenial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of theEPSS 0.7%CVE-2020-11243HIGHRRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service iEPSS 0.7%CVE-2020-3614—Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdragon Auto, SnapdragoEPSS 0.7%CVE-2019-14073—Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow when pEPSS 0.7%CVE-2020-11283—A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnEPSS 0.7%CVE-2019-2302—While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead to heap overflow. iEPSS 0.7%CVE-2019-10572—Improper check in video driver while processing data from video firmware can lead to integer overflow and then buffer overflow in SnapdragonEPSS 0.7%CVE-2014-9935—In TrustZone an integer overflow vulnerability leading to a buffer overflow could potentially occur in a DRM routine in all Android releasesEPSS 0.7%CVE-2016-10239—In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper inputEPSS 0.7%CVE-2022-40520HIGHStack based buffer overflow in CoreEPSS 0.7%