Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-35100HIGHPossible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, SnapdraEPSS 0.6%CVE-2021-35076HIGHPossible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon ComputEPSS 0.6%CVE-2021-35096HIGHImproper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, SnapdragoEPSS 0.6%CVE-2022-22064HIGHPossible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.6%CVE-2015-9029In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.EPSS 0.6%CVE-2018-13903u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon IndustrialEPSS 0.6%CVE-2014-9961In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-onEPSS 0.6%CVE-2021-30326HIGHPossible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup message inEPSS 0.6%CVE-2022-22083HIGHDenial of service due to memory corruption while extracting ape header from clips in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectEPSS 0.6%CVE-2016-10237If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android EPSS 0.6%CVE-2017-9712In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, if userspace provides a too-EPSS 0.6%CVE-2017-15850In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values frEPSS 0.6%CVE-2021-30329HIGHPossible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdragEPSS 0.6%CVE-2021-30328HIGHPossible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, SnapdragonEPSS 0.6%CVE-2018-11284Spoofed SMS can be used to send a large number of messages to the device which will in turn initiate a flood of registration updates with thEPSS 0.5%CVE-2016-5863In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing whiEPSS 0.5%CVE-2016-5347In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driEPSS 0.5%CVE-2019-10504Firmware not able to send EXT scan response to host within 1 sec due to resource consumption issue in Snapdragon Auto, Snapdragon Consumer IEPSS 0.5%CVE-2021-30332HIGHPossible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdragEPSS 0.5%CVE-2016-5858In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large,EPSS 0.5%