Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2016-10335—In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.EPSS 0.5%CVE-2016-10333—In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.EPSS 0.5%CVE-2016-10334—In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.EPSS 0.5%CVE-2014-9943—In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.EPSS 0.5%CVE-2022-25719HIGHInformation disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon ConnectEPSS 0.5%CVE-2014-9930—In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9929—In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially existEPSS 0.5%CVE-2014-9928—In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentialEPSS 0.5%CVE-2014-9925—In HDR in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentiallyEPSS 0.5%CVE-2014-9948—In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially EPSS 0.5%CVE-2014-9942—In Boot in all Android releases from CAF using the Linux kernel, a Use of Uninitialized Variable vulnerability could potentially exist.EPSS 0.5%CVE-2014-9949—In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially existEPSS 0.5%CVE-2014-9926—In GNSS in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9946—In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9923—In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentiallyEPSS 0.5%CVE-2014-9924—In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.EPSS 0.5%CVE-2015-9007—In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.EPSS 0.5%CVE-2017-7369—In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading toEPSS 0.5%CVE-2017-9685—In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After FrEPSS 0.5%CVE-2021-30343CRITICALImproper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in SnapdrEPSS 0.5%