Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2018-3562Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for MSM, Firefox OS for MEPSS 0.3%CVE-2022-25662MEDIUMInformation disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SnapdEPSS 0.3%CVE-2022-25688HIGHMemory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.3%CVE-2022-25686HIGHMemory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnecEPSS 0.3%CVE-2022-25687HIGHmemory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SEPSS 0.3%CVE-2023-43512HIGHBuffer Over-read in Qualcomm ESLEPSS 0.3%CVE-2019-10494Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon AuEPSS 0.3%CVE-2024-33014HIGHBuffer Over-read in WLAN HostEPSS 0.3%CVE-2022-25658HIGHMemory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function in Snapdragon Auto, EPSS 0.3%CVE-2022-25668HIGHMemory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,EPSS 0.3%CVE-2020-11179Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition. in Snapdragon AutEPSS 0.3%CVE-2023-21667MEDIUMBuffer Over-read in Bluetooth HOSTEPSS 0.3%CVE-2018-5826In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security pEPSS 0.3%CVE-2024-33049HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.3%CVE-2024-33070HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.3%CVE-2024-33071HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.3%CVE-2024-38397HIGHBuffer Over-read in WLAN Host CommunicationEPSS 0.3%CVE-2022-22063HIGHMemory corruption in CoreEPSS 0.3%CVE-2023-28543HIGHOut of Bounds read in SNPE LibraryEPSS 0.3%CVE-2022-33234HIGHMemory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon ConsumEPSS 0.3%