Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2023-33063HIGHUse After Free in DSP ServicesEPSS 0.7%KEVCVE-2018-13897—Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, SnapdrEPSS 0.7%CVE-2020-11281—Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in SnEPSS 0.7%CVE-2020-11287—Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in SnEPSS 0.7%CVE-2019-10510—BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote in Snapdragon Auto,EPSS 0.7%CVE-2022-22065HIGHOut of bound read in WLAN HOST due to improper length check can lead to DOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,EPSS 0.7%CVE-2020-11135—u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon InduEPSS 0.7%CVE-2020-11273HIGHHistogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null pointer access when hisEPSS 0.7%CVE-2020-11274HIGHDenial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdEPSS 0.7%CVE-2020-11303HIGHAccepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon ConnEPSS 0.7%CVE-2020-11176CRITICALWhile processing server certificate from IPSec server, certificate validation for subject alternative name API can cause heap overflow whichEPSS 0.7%CVE-2017-14883—In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if EPSS 0.7%CVE-2015-9213—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDEPSS 0.7%CVE-2015-9137—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDEPSS 0.7%CVE-2016-10429—In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and SnapdEPSS 0.7%CVE-2018-13902—Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decoding XTRA file in SnapEPSS 0.7%CVE-2014-10058—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD EPSS 0.7%CVE-2014-10063—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625 and SD 800, a fuse is not correctly blownEPSS 0.7%CVE-2014-10044—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 210/SD 212/SD 205,EPSS 0.7%CVE-2015-9025—In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.EPSS 0.7%