Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-8234—In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.EPSS 0.4%CVE-2018-5840—Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (AndEPSS 0.4%CVE-2018-5841—dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could leaEPSS 0.4%CVE-2018-11982—In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SDEPSS 0.4%CVE-2023-33025CRITICALBuffer Copy without Checking Size of Input in Data ModemEPSS 0.4%CVE-2023-21647MEDIUMImproper Input Validation in Bluetooth HOSTEPSS 0.4%CVE-2018-3565—While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MEPSS 0.4%CVE-2018-3580—Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releasesEPSS 0.4%CVE-2017-8273—In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feaEPSS 0.4%CVE-2021-1961MEDIUMPossible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute, SnapdragEPSS 0.4%CVE-2023-21653HIGHReachable Assertion in ModemEPSS 0.4%CVE-2022-22060HIGHReachable Assertion in ModemEPSS 0.4%CVE-2023-21661HIGHBuffer Over-read in WLAN FirmwareEPSS 0.4%CVE-2022-33223HIGHNull pointer dereference in ModemEPSS 0.4%CVE-2022-33304HIGHNULL pointers dereference in ModemEPSS 0.4%CVE-2022-33290HIGHNull pointer dereference in Bluetooth HOSTEPSS 0.4%CVE-2022-40504HIGHReachable assertion in ModemEPSS 0.4%CVE-2022-33285HIGHBuffer over-read in WLANEPSS 0.4%CVE-2022-40508HIGHReachable assertion in ModemEPSS 0.4%CVE-2022-33251HIGHReachable assertion in ModemEPSS 0.4%