Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2020-11239—Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned up properly in SnapEPSS 0.2%CVE-2019-2274—Improper Access Control for RPU write access from secure processor in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics CEPSS 0.2%CVE-2019-10480—Out of bound write can happen in WMI firmware event handler due to lack of validation of data received from WLAN firmware in Snapdragon AutoEPSS 0.2%CVE-2019-10605—Buffer overwrite can occur in IEEE80211 header filling function due to lack of range check of array index received from firmware in SnapdragEPSS 0.2%CVE-2018-5903—Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in Snapdragon Auto, SnaEPSS 0.2%CVE-2019-10600—Use of local variable as argument to netlink CB callback goes out of it scope when callback triggered lead to invalid stack memory in SnapdrEPSS 0.2%CVE-2019-14055—Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in SnaEPSS 0.2%CVE-2019-10603—Use after free issue occurs If the real device interface goes down and a route lookup is performed while sending a raw IPv6 message in SnapdEPSS 0.2%CVE-2019-10607—Out of bounds memcpy can occur by providing the embedded NULL character string and length greater than the actual string length in SnapdragoEPSS 0.2%CVE-2019-10601—Out of bound access can occur while processing firmware event due to lack of validation of WMI message received from firmware in Snapdragon EPSS 0.2%CVE-2019-14007—Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channeEPSS 0.2%CVE-2019-10595—Possible buffer overwrite in message handler due to lack of validation of tid value calculated from packets received from firmware in SnapdrEPSS 0.2%CVE-2019-10598—Out of bound access can occur while processing peer info in IBSS connection mode due to lack of upper bounds check to ensure that for loop fEPSS 0.2%CVE-2020-3684—u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader and applies them witEPSS 0.2%CVE-2020-3621—u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size results into EPSS 0.2%CVE-2020-3665—A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firmware being out of raEPSS 0.2%CVE-2019-10536—Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is not set to NULL on EPSS 0.2%CVE-2019-2267—Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in Snapdragon Auto, SnapEPSS 0.2%CVE-2020-3618—NULL exception due to accessing bad pointer while posting events on RT FIFO in Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired InfraEPSS 0.2%CVE-2020-11309—Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, SnapEPSS 0.2%