Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2020-11181—Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in SnapEPSS 0.2%CVE-2017-18172—In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting in an Integer OverfloEPSS 0.2%CVE-2018-11950—Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850EPSS 0.2%CVE-2018-11968—Improper check before assigning value can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdragEPSS 0.2%CVE-2018-12012—While updating blacklisting region shared buffered memory region is not validated against newly updated black list, causing boot-up to be coEPSS 0.2%CVE-2018-13910—Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectivity, Snapdragon ConsEPSS 0.2%CVE-2018-11999—Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versEPSS 0.2%CVE-2018-11970—TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics ConnectivitEPSS 0.2%CVE-2018-5913—A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto, Snapdragon Compute,EPSS 0.2%CVE-2018-11966—Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdrEPSS 0.2%CVE-2019-2346—Firmware is getting into loop of overwriting memory when scan command is given from host because of improper validation. in Snapdragon CompuEPSS 0.2%CVE-2019-2316—When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, EPSS 0.2%CVE-2026-24079HIGHMissing Authentication for Critical Function in Data ModemEPSS 0.2%CVE-2018-11826—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on integer overfloEPSS 0.2%CVE-2018-5839—Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, SnaEPSS 0.2%CVE-2018-5914—Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using the incoming data in SEPSS 0.2%CVE-2020-11183—A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in EPSS 0.2%CVE-2019-2250—Kernel can write to arbitrary memory address passed by user while freeing/stopping a thread in Snapdragon Compute, Snapdragon Consumer IOT, EPSS 0.2%CVE-2019-10618—Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdragon Connectivity in QCEPSS 0.2%CVE-2020-11150—Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of poinEPSS 0.2%