Vulnerabilities in Qualcomm, Inc.

2,934 results
Vexday analysis

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2022-22078MEDIUMDenial of service in BOOT when partition size for a particular partition is requested due to integer overflow when blocks are calculated in EPSS 0.2%CVE-2025-27071HIGHBuffer Copy Without Checking Size of Input in Powerline Communication FirmwareEPSS 0.2%CVE-2019-10535Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop iEPSS 0.2%CVE-2021-1969MEDIUMImproper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure toEPSS 0.2%CVE-2017-11007In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of stEPSS 0.2%CVE-2019-10490Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto, SnapdragEPSS 0.2%CVE-2018-5888While processing the system path, an out of bounds access can occur in Android releases from CAF using the linux kernel (Android for MSM, FiEPSS 0.2%CVE-2021-30266MEDIUMPossible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, SnapEPSS 0.2%CVE-2018-11277In Snapdragon (Automobile, Mobile, Wear) in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD EPSS 0.2%CVE-2017-18154A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, EPSS 0.2%CVE-2019-10484Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previoEPSS 0.2%CVE-2024-21455HIGHUntrusted Pointer Dereference in DSP ServiceEPSS 0.2%CVE-2022-25664MEDIUMInformation disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon ConnectiviEPSS 0.2%CVE-2018-3573In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while relocating kernel images wEPSS 0.2%CVE-2021-1968MEDIUMImproper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure toEPSS 0.2%CVE-2021-1889HIGHPossible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,EPSS 0.2%CVE-2020-11266Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired InfrastructEPSS 0.2%CVE-2023-21629MEDIUMDouble Free in ModemEPSS 0.2%CVE-2018-3570In the cpuidle driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, the list_foEPSS 0.2%CVE-2022-22079MEDIUMBuffer Over-read in BOOTEPSS 0.2%