Vulnerabilidades em Qualcomm, Inc.

2.976 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-14060—Uninitialized stack data gets used If memory is not allocated for blob or if the allocated blob is less than the struct size required due toEPSS 0.2%CVE-2019-10604—Possibility of heap-buffer-overflow during last iteration of loop while populating image version information in diag command response packetEPSS 0.2%CVE-2019-10558—While transferring data from APPS to DSP, Out of bound in FastRPC HLOS Driver due to the data buffer which can be controlled by DSP in SnapdEPSS 0.2%CVE-2019-2246—Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel in Snapdragon Auto,EPSS 0.2%CVE-2018-11298—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing SET_PASSPOINT_LEPSS 0.2%CVE-2018-11265—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possible buffer overflow while iEPSS 0.2%CVE-2019-14135—Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.2%CVE-2019-14026—Possible buffer overflow in WLAN WMI handler due to lack of ssid length check when copying data in Snapdragon Auto, Snapdragon Compute, SnapEPSS 0.2%CVE-2019-14027—Buffer overflow due to lack of upper bound check on channel length which is used for a loop. in Snapdragon Compute, Snapdragon Connectivity,EPSS 0.2%CVE-2019-14050—Out-of-bound writes occurs due to lack of check of buffer size will cause buffer overflow only in 32bit architecture. in Snapdragon Auto, SnEPSS 0.2%CVE-2019-10569—Stack buffer overflow due to instance id is misplaced inside definition of hardware accelerated effects in makefile in Snapdragon Auto, SnapEPSS 0.2%CVE-2019-14051—Subsequent additions performed during Module loading while allocating the memory would lead to integer overflow and then to buffer overflow EPSS 0.2%CVE-2019-14036—Possible buffer overflow issue in error processing due to improper validation of array index value in Snapdragon Auto, Snapdragon Consumer EEPSS 0.2%CVE-2018-11886—In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check while calculating EPSS 0.2%CVE-2018-3595—Anti-rollback can be bypassed in replay scenario during app loading due to improper error handling of RPMB writes in snapdragon automobile, EPSS 0.2%CVE-2019-14015—A stack-based buffer overflow exists in the initialization of the identification stage due to lack of check on the number of templates proviEPSS 0.2%CVE-2018-11888—Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon ComEPSS 0.2%CVE-2019-10580—When kernel thread unregistered listener, Use after free issue happened as the listener client`s private data has been already freed in SnapEPSS 0.2%CVE-2019-14100—Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.2%CVE-2018-3569—A buffer over-read can occur during a fast initial link setup (FILS) connection in Android releases from CAF using the linux kernel (AndroidEPSS 0.2%