Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2018-5868—Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SDEPSS 0.3%CVE-2017-18294—While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size of ELF64 header size EPSS 0.3%CVE-2017-18282—Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MEPSS 0.3%CVE-2017-18296—Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdragon Automobile, SnapEPSS 0.3%CVE-2017-18298—Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versEPSS 0.3%CVE-2017-18304—Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small Cell SoC, SnapdragonEPSS 0.3%CVE-2017-18297—Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, SD 625, SD 650/52, SDEPSS 0.3%CVE-2025-21484HIGHBuffer Over-read in Data Network Stack & ConnectivityEPSS 0.3%CVE-2025-21487HIGHBuffer Over-read in Data Network Stack & ConnectivityEPSS 0.3%CVE-2018-11867—Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile EPSS 0.3%CVE-2025-21448HIGHBuffer Over-read in WLAN FirmwareEPSS 0.3%CVE-2025-21429HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2018-11882—Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA6EPSS 0.3%CVE-2025-21430HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2025-21434HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2025-21435HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.3%CVE-2017-18313—Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the authenticated WCNSSEPSS 0.3%CVE-2018-11856—Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 835, SEPSS 0.3%CVE-2023-43551CRITICALImproper Authentication in Multi-Mode Call ProcessorEPSS 0.3%CVE-2024-33068HIGHUse After Free in WLAN Host CommunicationEPSS 0.3%