Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2019-10505Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, SEPSS 0.7%CVE-2019-10522While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon ConsuEPSS 0.7%CVE-2019-10542Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in SnEPSS 0.7%CVE-2019-14080Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdragon Auto, Snapdragon CEPSS 0.7%CVE-2019-10528Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, SnaEPSS 0.7%CVE-2019-2268Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics ConnecEPSS 0.7%CVE-2019-10565Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, SnapEPSS 0.7%CVE-2019-2303SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, SnapdragEPSS 0.7%CVE-2020-11243HIGHRRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service iEPSS 0.7%CVE-2020-11255HIGHDenial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of theEPSS 0.7%CVE-2019-14073Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow when pEPSS 0.7%CVE-2019-10572Improper check in video driver while processing data from video firmware can lead to integer overflow and then buffer overflow in SnapdragonEPSS 0.7%CVE-2020-3614Possible buffer overflow while copying the frame to local buffer due to lack of check of length before copying in Snapdragon Auto, SnapdragoEPSS 0.7%CVE-2019-2302While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead to heap overflow. iEPSS 0.7%CVE-2014-10058In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD EPSS 0.7%CVE-2015-9137In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDEPSS 0.7%CVE-2014-10044In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 210/SD 212/SD 205,EPSS 0.7%CVE-2015-9213In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDEPSS 0.7%CVE-2016-10429In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and SnapdEPSS 0.7%CVE-2014-10063In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625 and SD 800, a fuse is not correctly blownEPSS 0.7%