Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-30327HIGHBuffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, SnapdragoEPSS 0.2%CVE-2018-5838—Improper Validation of Array Index In the adreno OpenGL driver in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, an out-of-boEPSS 0.2%CVE-2020-11175—u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due to impropEPSS 0.2%CVE-2019-10597—kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2019-10615—u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of keymasterEPSS 0.2%CVE-2019-13998—u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corrupEPSS 0.2%CVE-2019-13995—u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corrupEPSS 0.2%CVE-2019-10582—Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, SnEPSS 0.2%CVE-2019-2339—Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon CompuEPSS 0.2%CVE-2020-11246HIGHA double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, SnapdEPSS 0.2%CVE-2020-11242HIGHUser could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contentEPSS 0.2%CVE-2019-10548—While trying to obtain datad ipc handle during DPL initialization, Heap use-after-free issue can occur if modem SSR occurs at same time in SEPSS 0.2%CVE-2019-14068—Out of bound access in msm routing due to lack of check of size before accessing in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsumerEPSS 0.2%CVE-2019-14028—Buffer overwrite during memcpy due to lack of check on SSID length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivitEPSS 0.2%CVE-2019-14087—Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon Consumer IOT, SnapdEPSS 0.2%CVE-2019-10602—Potential use-after-free heap error during Validate/Present calls on display HW composer in Snapdragon Auto, Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2019-14024—Possible stack-use-after-scope issue in NFC usecase for card emulation in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile in MEPSS 0.2%CVE-2020-11234HIGHWhen sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting iEPSS 0.2%CVE-2020-11205—u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, SnEPSS 0.2%CVE-2019-2288—Out of bound write in TZ while copying the secure dump structure on HLOS provided buffer as a part of memory dump in Snapdragon Auto, SnapdrEPSS 0.2%