Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-2337—While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device toEPSS 0.7%CVE-2019-14010—The device may enter into error state when some tool or application gets failure at 1st buffer map all and performs 2nd buffer map which hapEPSS 0.7%CVE-2019-10485—Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, EPSS 0.7%CVE-2020-3645—Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon CompuEPSS 0.7%CVE-2021-30302HIGHImproper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, SnapdraEPSS 0.7%CVE-2020-3651—Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames. in Snapdragon Auto,EPSS 0.7%CVE-2017-11088—Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSEPSS 0.7%CVE-2015-8995—In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.EPSS 0.6%CVE-2014-9964—In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.EPSS 0.6%CVE-2014-9932—In TrustZone, an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel due to an imprEPSS 0.6%CVE-2015-8998—In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.EPSS 0.6%CVE-2019-10482—Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channeEPSS 0.6%CVE-2019-2335—While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon CompuEPSS 0.6%CVE-2014-9962—In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.EPSS 0.6%CVE-2016-10418—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM92EPSS 0.6%CVE-2021-30312HIGHImproper authentication of sub-frames of a multicast AMSDU frame can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, EPSS 0.6%CVE-2014-9965—In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.EPSS 0.6%CVE-2015-9027—In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.EPSS 0.6%CVE-2015-9026—In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.EPSS 0.6%CVE-2016-5864—In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userEPSS 0.6%