Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2024-38405HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2024-23385HIGHReachable Assertion in ModemEPSS 0.3%CVE-2024-38403HIGHBuffer Over-read in WLAN FirmwareEPSS 0.3%CVE-2024-33068HIGHUse After Free in WLAN Host CommunicationEPSS 0.3%CVE-2018-13905—KGSL syncsource lock not handled properly during syncsource cleanup can lead to use after free issue in Snapdragon Auto, Snapdragon ConsumerEPSS 0.3%CVE-2025-21428HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2018-13900—Use-after-free vulnerability will occur as there is no protection for the route table`s rule in IPA driver in Snapdragon Auto, Snapdragon CoEPSS 0.3%CVE-2024-38404HIGHBuffer Over-read in Multi Mode Call ProcessorEPSS 0.3%CVE-2017-18292—Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile andEPSS 0.3%CVE-2017-18299—Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and SEPSS 0.3%CVE-2020-3694—u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, SnapdragEPSS 0.3%CVE-2026-24084HIGHInsecure Security Identifier Mechanism in Multi-Mode Call ProcessorEPSS 0.3%CVE-2018-11994—SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile, Snapdragon Mobile aEPSS 0.2%CVE-2018-11938—Improper input validation for argument received from HLOS can lead to buffer overflows and unexpected behavior in Snapdragon Auto, SnapdragoEPSS 0.2%CVE-2021-35093MEDIUMPossible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service in BlueCEPSS 0.2%CVE-2024-49847HIGHBuffer Over-read in Multi-Mode Call ProcessorEPSS 0.2%CVE-2019-10567—There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing commands could alEPSS 0.2%CVE-2018-11875—Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.EPSS 0.2%CVE-2017-18280—In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 4EPSS 0.2%CVE-2018-11874—Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SDEPSS 0.2%