Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2023-33089HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.5%CVE-2023-33097HIGHBuffer Over-read in WLAN FirmwareEPSS 0.5%CVE-2023-33098HIGHBuffer Over-read in WLAN FirmwareEPSS 0.5%CVE-2023-33081HIGHBuffer over-read in WLAN FirmwareEPSS 0.5%CVE-2023-33041HIGHReachable assertion in WLAN FirmwareEPSS 0.5%CVE-2014-9945In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.EPSS 0.5%CVE-2017-8240In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.EPSS 0.5%CVE-2016-10333In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.EPSS 0.5%CVE-2016-10335In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.EPSS 0.5%CVE-2016-10334In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.EPSS 0.5%CVE-2017-9678In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur dEPSS 0.5%CVE-2021-1904MEDIUMChild process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon AuEPSS 0.5%CVE-2016-10389In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto theEPSS 0.5%CVE-2014-9943In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.EPSS 0.5%CVE-2021-35082CRITICALImproper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has beeEPSS 0.5%CVE-2021-30347CRITICALImproper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in EPSS 0.5%CVE-2022-25670HIGHDenial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectivitEPSS 0.5%CVE-2017-8268In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buEPSS 0.5%CVE-2014-9930In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9929In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially existEPSS 0.5%