Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14115—u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result EPSS 0.2%CVE-2018-13920—Use-after-free condition due to Improper handling of hrtimers when the PMU driver tries to access its events in Snapdragon Auto, Snapdragon EPSS 0.2%CVE-2018-11927—Improper input validation on input which is used as an array index will lead to an out of bounds issue while processing AP find event from fEPSS 0.2%CVE-2018-11967—Signature verification of the skel library could potentially be disabled as the memory region on the remote subsystem in which the library iEPSS 0.2%CVE-2015-9217—In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 20EPSS 0.2%CVE-2019-2326—Data token is received from ADSP and is used without validation as an index into the array leads to out of bound access in Snapdragon Auto, EPSS 0.2%CVE-2020-3646—u'Buffer overflow seen as the destination buffer size is lesser than the source buffer size in video application' in Snapdragon Compute, SnaEPSS 0.2%CVE-2020-11130—u'Possible buffer overflow in WIFI hal process due to copying data without checking the buffer length' in Snapdragon Auto, Snapdragon ComputEPSS 0.2%CVE-2025-27057HIGHBuffer Over-read in WLAN HostEPSS 0.2%CVE-2018-11925—Data length received from firmware is not validated against the max allowed size which can result in buffer overflow. in Snapdragon Auto, SnEPSS 0.2%CVE-2017-11004—A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ807EPSS 0.2%CVE-2018-12013—Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, SnapdraEPSS 0.2%CVE-2017-18321—Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.EPSS 0.2%CVE-2017-18323—Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions EPSS 0.2%CVE-2017-18322—Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDEPSS 0.2%CVE-2017-18326—Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM9615, MDM9625, MDM96EPSS 0.2%CVE-2018-3583—A buffer overflow can occur while processing an extscan hotlist event in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, SnapEPSS 0.2%CVE-2017-18324—Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, EPSS 0.2%CVE-2017-18319—Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635MEPSS 0.2%CVE-2018-13896—XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_EPSS 0.2%