Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2018-11288—Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended regioEPSS 0.2%CVE-2019-2281—An unauthenticated bitmap image can be loaded in to memory and subsequently cause execution of unverified code. in Snapdragon Compute, SnapdEPSS 0.2%CVE-2017-18332—Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear iEPSS 0.2%CVE-2017-18327—Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear iEPSS 0.2%CVE-2025-21463HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.2%CVE-2021-1956MEDIUMImproper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Snapdragon CEPSS 0.2%CVE-2021-1960MEDIUMImproper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, SnEPSS 0.2%CVE-2018-13888—There is potential for memory corruption in the RIL daemon due to de reference of memory outside the allocated array length in RIL in SnapdrEPSS 0.2%CVE-2018-11864—Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiEPSS 0.2%CVE-2018-5883—Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer IOT, SnapdraEPSS 0.2%CVE-2018-11845—Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdragon Auto, SnapdragonEPSS 0.2%CVE-2018-11820—Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdragon Auto, SEPSS 0.2%CVE-2018-11847—Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kEPSS 0.2%CVE-2018-5866—While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon Wear in version MDM9EPSS 0.2%CVE-2018-11877—When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon MobiEPSS 0.2%CVE-2018-11879—When the buffer length passed is very large, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in veEPSS 0.2%CVE-2018-11922HIGHConfigurations in Android BuildEPSS 0.2%CVE-2018-5880—Improper data length check while processing an event report indication can lead to a buffer overflow in snapdragon mobile and snapdragon weaEPSS 0.2%CVE-2020-3693—u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snapdragon Auto, SnapdraEPSS 0.2%CVE-2018-5912—Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile, Snapdragon Mobile inEPSS 0.2%