Vulnerabilidades em Qualcomm, Inc.

2.971 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2016-5862—When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, EPSS 0.5%CVE-2017-18170—Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SEPSS 0.5%CVE-2023-28588HIGHInteger Overflow or Wraparound in Bluetooth HostEPSS 0.5%CVE-2017-18283—Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212EPSS 0.5%CVE-2017-14869—In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FEPSS 0.5%CVE-2021-1906MEDIUMImproper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon ComputEPSS 0.5%KEVCVE-2015-0575—In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuraEPSS 0.5%CVE-2021-35083HIGHPossible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon CoEPSS 0.5%CVE-2016-10336—In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.EPSS 0.5%CVE-2016-10332—In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.EPSS 0.5%CVE-2017-9680—In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a drEPSS 0.5%CVE-2016-10337—In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.EPSS 0.5%CVE-2017-9679—In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory EPSS 0.5%CVE-2017-18171—Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in SnapdragoEPSS 0.5%CVE-2019-14040—Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in SnapEPSS 0.5%CVE-2020-11154—u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before copying' in Snapdragon EPSS 0.5%CVE-2020-11155—u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.' in Snapdragon AutoEPSS 0.5%CVE-2022-22096CRITICALMemory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in SnapdragoEPSS 0.5%CVE-2023-33044HIGHReachable Assertion in Data ModemEPSS 0.5%CVE-2023-33043HIGHReachable Assertion in ModemEPSS 0.5%