Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2017-18315—Buffer over-read vulnerabilities in an older version of ASN.1 parser in Snapdragon Mobile in versions SD 600.EPSS 0.2%CVE-2017-18316—Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon WeEPSS 0.2%CVE-2021-1931MEDIUMPossible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapdragon CompEPSS 0.2%CVE-2018-11267—In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9615, MDM9640, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SEPSS 0.2%CVE-2020-3701—Use after free issue while processing error notification from camx driver due to not properly releasing the sequence data in Snapdragon MobiEPSS 0.2%CVE-2025-47328HIGHBuffer Over-read in WLAN HALEPSS 0.2%CVE-2017-18331—Improper access control on secure display buffers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM96EPSS 0.2%CVE-2017-18328—Use after free in QSH client rule processing in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9640, MDM96EPSS 0.2%CVE-2019-2306—Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdragon Connectivity, SEPSS 0.2%CVE-2018-5891—While processing modem SSR after IMS is registered, the IMS data daemon is restarted but the ipc_dataHandle is no longer available. ConsequeEPSS 0.2%CVE-2019-10617—Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registEPSS 0.2%CVE-2022-33253HIGHBuffer over-read in WLANEPSS 0.2%CVE-2020-11129—u'During the error occurrence in capture request, the buffer is freed and later accessed causing the camera APP to fail due to memory use-afEPSS 0.2%CVE-2018-13916—Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in SnapdEPSS 0.2%CVE-2019-14071—Compromised reset handler may bypass access control due to AC config is being reset if debug path is enabled to collect secure or non-secureEPSS 0.2%CVE-2020-3617—u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing the field and leads EPSS 0.2%CVE-2017-15835—In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data DesEPSS 0.2%CVE-2019-2251—If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially cause stack buffer overfEPSS 0.2%CVE-2020-3642—Use after free issue in camera applications when used randomly over multiple operations due to pointer not set to NULL after free/destroy ofEPSS 0.2%CVE-2019-14047—While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to the IPA HW commit lEPSS 0.2%