Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-10537—Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eEPSS 0.2%CVE-2019-14009—Out of bound memory access while processing TZ command handler due to improper input validation on response length received from user in SnaEPSS 0.2%CVE-2019-14044—Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close in Snapdragon ConsuEPSS 0.2%CVE-2019-14074—u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon Compute, SnEPSS 0.2%CVE-2025-21427HIGHBuffer Over-read in Data HLOS - LNXEPSS 0.2%CVE-2019-14085—Possible Integer underflow in WLAN function due to lack of check of data received from user side in Snapdragon Auto, Snapdragon Compute, SnaEPSS 0.2%CVE-2019-14105—Kernel was reading the CSL defined reserved field as uint16 instead of uint32 which could lead to memory overflow in Snapdragon Industrial IEPSS 0.2%CVE-2019-14023—String format issue will occur while processing HLOS data as there is no user input validation to ensure inputs are properly NULL terminatedEPSS 0.2%CVE-2019-14029—Use-after-free in graphics module due to destroying already queued syncobj in error case in Snapdragon Auto, Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2018-11860—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a potential buffer over flow couEPSS 0.2%CVE-2020-11127—u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during the validation of secuEPSS 0.2%CVE-2019-10606—Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdragon Auto, Snapdragon CEPSS 0.2%CVE-2019-10585—Possible integer overflow happens when mmap find function will increment refcount every time when it invokes and can lead to use after free EPSS 0.2%CVE-2018-11902—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check EPSS 0.2%CVE-2019-14054—Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to normal cold boot path in EPSS 0.2%CVE-2019-10481—Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly from the WLAN FW in EPSS 0.2%CVE-2019-14049—Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in SnapdEPSS 0.2%CVE-2018-11895—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check ValidationEPSS 0.2%CVE-2019-2329—Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application. in Snapdragon CompuEPSS 0.2%CVE-2018-11262—In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out tEPSS 0.2%