Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14066—Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Numbers or checking FeaturEPSS 0.2%CVE-2019-14032—Memory use after free issue in audio due to lack of resource control in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, SnapdrEPSS 0.2%CVE-2019-2321—Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, SnapdrEPSS 0.2%CVE-2019-14046—Out of bound access while allocating memory for an array in camera due to improper validation of elements parameters in Snapdragon Auto, SnaEPSS 0.2%CVE-2019-14122—Memory failure in SKB if it fails to to add the requested padding to the skb in low memory targets or targets with major memory fragmentatioEPSS 0.2%CVE-2018-11897—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing diag event afteEPSS 0.2%CVE-2020-11199—HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in SnapdragoEPSS 0.2%CVE-2019-14021—Possible buffer overrun when processing EFS filename and payload sent over diag interface due to lack of check for filename length and payloEPSS 0.2%CVE-2020-11237HIGHMemory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in SnapdragonEPSS 0.2%CVE-2019-14018—Possible out of bound array access as there is no check on carrier index passed in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer EPSS 0.2%CVE-2017-15825—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a gpt update, aEPSS 0.2%CVE-2019-14034—Use after free while processing eeprom query as there is a chance to not unlock mutex after error occurs in Snapdragon Auto, Snapdragon CompEPSS 0.2%CVE-2019-10583—Use after free issue occurs when camera access sensors data through direct report mode in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.2%CVE-2019-2315—While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure environment. in EPSS 0.2%CVE-2019-14030—The size of a buffer is determined by addition and multiplications operations that have the potential to overflow due to lack of bound checkEPSS 0.2%CVE-2020-3625—When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon AutEPSS 0.2%CVE-2018-11838—Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsumeEPSS 0.2%CVE-2020-11245HIGHUnintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdragon CompuEPSS 0.2%CVE-2018-11851—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on input received EPSS 0.2%CVE-2019-14000—Lack of check that the RX FIFO write index that is read from shared RAM is less than the FIFO size results into memory corruption and potentEPSS 0.2%