Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-17766—In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received EPSS 0.6%CVE-2017-18125—In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212EPSS 0.6%CVE-2018-5837—In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD 212/SD 205,EPSS 0.6%CVE-2020-11278—Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon ConEPSS 0.6%CVE-2020-11270—Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter EPSS 0.6%CVE-2020-11280—Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due to impropEPSS 0.6%CVE-2014-9967—In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.EPSS 0.6%CVE-2015-9033—In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.EPSS 0.6%CVE-2015-9020—In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.EPSS 0.6%CVE-2016-10238—In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.EPSS 0.6%CVE-2014-9933—Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not havEPSS 0.6%CVE-2015-9003—In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.EPSS 0.6%CVE-2016-10338—In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.EPSS 0.6%CVE-2015-9000—In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using thEPSS 0.6%CVE-2016-10341—In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.EPSS 0.6%CVE-2015-9002—In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the EPSS 0.6%CVE-2017-11069—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch IEPSS 0.6%CVE-2020-11296—Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon ConEPSS 0.6%CVE-2016-5860—In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very laEPSS 0.6%CVE-2016-5859—In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very larEPSS 0.6%